fix parameter name in checkout action #590
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This is a fix to the change we made in #280 in order to avoid secret scanning blocking our PR workflow.
Either this has never worked, or the param changed, but currently the
depthparam is being ignored, meaning only the latest commit is checked out as part of the CI. However, the intention here was to fetch all ancestor commits of the current branch (but not the entire repository) so that secret scanning is able to scan every commit in the PR.After fixing the param, I tested this by pushing two commits: first one with a fake credential in, second one that removes the credential. It correctly failed the check.
Note: regardless of what this PR check is doing, the entire git history is still scanned on main, so secrets cannot slip through without us being alerted.