From 32d20ad457c9070f34f72b6d328a118aae563d0e Mon Sep 17 00:00:00 2001 From: Silabs-ThieuVu <65759766+Silabs-ThieuVu@users.noreply.github.com> Date: Wed, 13 Nov 2024 15:17:29 +0700 Subject: [PATCH] Update 01-run-trofflehog.yaml --- .github/workflows/01-run-trofflehog.yaml | 20 +++++++------------- 1 file changed, 7 insertions(+), 13 deletions(-) diff --git a/.github/workflows/01-run-trofflehog.yaml b/.github/workflows/01-run-trofflehog.yaml index f5d9f78..84dee1e 100644 --- a/.github/workflows/01-run-trofflehog.yaml +++ b/.github/workflows/01-run-trofflehog.yaml @@ -8,20 +8,14 @@ jobs: runs-on: ubuntu-latest steps: - - name: Set up Python 3.x - uses: actions/setup-python@v2 + - name: Checkout code + uses: actions/checkout@v4.1.7 with: - python-version: '3.x' - - - name: Install TruffleHog - run: | - python -m pip install --upgrade pip - pip install trufflehog - trufflehog -V - - - name: Run TruffleHog on the repository - run: | - trufflehog --json https://github.com/${{ github.repository }} > trufflehog_report.json + fetch-depth: 0 + - name: Secret Scanning + uses: trufflesecurity/trufflehog@main + with: + extra_args: --only-verified - name: Upload TruffleHog Report uses: actions/upload-artifact@v4.3.4