diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index b48fd82..54efa3e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -23,3 +23,16 @@ jobs: - run: npm ci - run: npm run build - run: npm test + + gitleaks: + name: Secret scan (gitleaks) + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Run gitleaks + uses: gitleaks/gitleaks-action@v2 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/SECURITY.md b/SECURITY.md index dba414e..da1733b 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -14,6 +14,13 @@ Email **security@jordannewell.com** with: **Do not open a public GitHub issue** for security reports. +If you have a PGP key, encrypt your report. GPG fingerprint of the project's +reporting key: + +``` +67567DC5E7C5353F85F2AF0DAC05D3F3E0EFA32A +``` + ## Response timeline - **Acknowledgment:** within 72 hours