File tree Expand file tree Collapse file tree 2 files changed +30
-1
lines changed Expand file tree Collapse file tree 2 files changed +30
-1
lines changed Original file line number Diff line number Diff line change
1
+ name : Secrets Scan
2
+ on :
3
+ pull_request :
4
+ types : [opened, synchronize, reopened]
5
+ jobs :
6
+ security-secrets :
7
+ runs-on : ubuntu-latest
8
+ steps :
9
+ - uses : actions/checkout@v4
10
+ with :
11
+ fetch-depth : ' 2'
12
+ ref : ' ${{ github.event.pull_request.head.ref }}'
13
+ - run : |
14
+ git reset --soft HEAD~1
15
+ - name : Install Talisman
16
+ run : |
17
+ # Download Talisman
18
+ wget https://github.com/thoughtworks/talisman/releases/download/v1.37.0/talisman_linux_amd64 -O talisman
19
+
20
+ # Checksum verification
21
+ checksum=$(sha256sum ./talisman | awk '{print $1}')
22
+ if [ "$checksum" != "8e0ae8bb7b160bf10c4fa1448beb04a32a35e63505b3dddff74a092bccaaa7e4" ]; then exit 1; fi
23
+
24
+ # Make it executable
25
+ chmod +x talisman
26
+ - name : Run talisman
27
+ run : |
28
+ # Run Talisman with the pre-commit hook
29
+ ./talisman --githook pre-commit
Original file line number Diff line number Diff line change 1
1
threshold: medium
2
2
fileignoreconfig:
3
3
- filename: package-lock.json
4
- checksum: 21fac429ab80d0ffe81207cbd7e1cc33972d9410693cd4cfd4d57b00bc2f5233
4
+ checksum: 1cfef37e0c387725843e0178fa7587e6c7c55ca61d938995244384ecc899cab7
5
5
version: "1.0"
You can’t perform that action at this time.
0 commit comments