Skip to content

changed permissions for scorecard action to fix a check problem #57

changed permissions for scorecard action to fix a check problem

changed permissions for scorecard action to fix a check problem #57

Workflow file for this run

name: Leaked Secrets Scan
on:
push:
branches: [ develop ]
pull_request:
branches: [ main ]
permissions: # added using https://github.com/step-security/secure-workflows
contents: read
jobs:
TruffleHog:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@18bf8ad2ca49c14cbb28b91346d626ccfb00c518 # v2.1.0
with:
egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs
- name: Checkout code
uses: actions/checkout@ac593985615ec2ede58e132d2e21d2b1cbd6127c # v3.3.0
with:
fetch-depth: 0
- name: TruffleHog OSS
uses: trufflesecurity/trufflehog@bc27fef7bc006152f3fa872c4679f0038d55e925 # main
with:
path: ./
base: ${{ github.event.repository.default_branch }}
head: HEAD
extra_args: --debug --only-verified