diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml new file mode 100644 index 0000000..1279028 --- /dev/null +++ b/.github/workflows/secret-scan.yml @@ -0,0 +1,27 @@ +############################################################################### +# Secret scan +# +# Calls the public org scanner on main. Allow-list updates there apply on the +# next run, with no pin bump in this repo. gitleaks git scans the full history. +############################################################################### + +name: Secret scan + +on: + pull_request: + types: [opened, synchronize, reopened] + push: + branches: [main] + schedule: + - cron: "0 3 1 * *" + workflow_dispatch: + +permissions: + contents: read + +jobs: + gitleaks: + name: Secret Scan (Gitleaks) + permissions: + contents: read + uses: m0-platform/secret-scan/.github/workflows/secret-scan.yml@main