-
-
Notifications
You must be signed in to change notification settings - Fork 0
29 lines (29 loc) · 1.01 KB
/
Copy pathsecret-scanner.yml
File metadata and controls
29 lines (29 loc) · 1.01 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
# SPDX-License-Identifier: MPL-2.0
#
# Standalone secret scan. Previously a thin caller of
# `hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml`
# with `secrets: inherit`; that cross-repo dependency startup-failed (the
# caller's `concurrency:` block stacked on the reusable's — the BP008 class,
# see spark-theatre-gate.yml) and required inheriting org secrets. This
# self-contained version runs a pure-shell high-confidence scan
# (tools/ci/secret-scan-standalone.sh), needs no secrets, and as a normal
# workflow can keep its concurrency block.
name: Secret Scanner
on:
pull_request:
push:
branches: [main]
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
scan:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Checkout code
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Run standalone secret scan
run: ./tools/ci/secret-scan-standalone.sh