diff --git a/.github/workflows/trufflehog.yml b/.github/workflows/trufflehog.yml new file mode 100644 index 0000000..f93ba21 --- /dev/null +++ b/.github/workflows/trufflehog.yml @@ -0,0 +1,26 @@ +name: Trufflehog +on: [pull_request, push, workflow_dispatch] + +jobs: + trufflehog: + name: trufflehog + runs-on: ubuntu-latest + + steps: + - name: Checkout code + uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Secret Scanning + uses: trufflesecurity/trufflehog@main + with: + extra_args: --only-verified + + # Scan entire branch + - name: scan-push + uses: trufflesecurity/trufflehog@main + with: + base: "" + head: ${{ github.ref_name }} + extra_args: --only-verified