File tree Expand file tree Collapse file tree 2 files changed +30
-1
lines changed
Expand file tree Collapse file tree 2 files changed +30
-1
lines changed Original file line number Diff line number Diff line change 1+ name : Secrets Scan
2+ on :
3+ pull_request :
4+ types : [opened, synchronize, reopened]
5+ jobs :
6+ security-secrets :
7+ runs-on : ubuntu-latest
8+ steps :
9+ - uses : actions/checkout@v4
10+ with :
11+ fetch-depth : ' 2'
12+ ref : ' ${{ github.event.pull_request.head.ref }}'
13+ - run : |
14+ git reset --soft HEAD~1
15+ - name : Install Talisman
16+ run : |
17+ # Download Talisman
18+ wget https://github.com/thoughtworks/talisman/releases/download/v1.37.0/talisman_linux_amd64 -O talisman
19+
20+ # Checksum verification
21+ checksum=$(sha256sum ./talisman | awk '{print $1}')
22+ if [ "$checksum" != "8e0ae8bb7b160bf10c4fa1448beb04a32a35e63505b3dddff74a092bccaaa7e4" ]; then exit 1; fi
23+
24+ # Make it executable
25+ chmod +x talisman
26+ - name : Run talisman
27+ run : |
28+ # Run Talisman with the pre-commit hook
29+ ./talisman --githook pre-commit
Original file line number Diff line number Diff line change 11threshold: medium
22fileignoreconfig:
33 - filename: package-lock.json
4- checksum: 21fac429ab80d0ffe81207cbd7e1cc33972d9410693cd4cfd4d57b00bc2f5233
4+ checksum: 1cfef37e0c387725843e0178fa7587e6c7c55ca61d938995244384ecc899cab7
55version: "1.0"
You can’t perform that action at this time.
0 commit comments