Skip to content

Commit 4b06dc7

Browse files
fix(ci): drop the retired inline trufflehog job (#37)
The permission fix has landed, so `Secret Scanner` now **starts** — `gitleaks`, `rust-secrets` and `shell-secrets` all pass. But the workflow still reports **red**, because of a vestigial inline `trufflehog` job. `secret-scanner-reusable.yml` **deliberately retired** TruffleHog as redundant — from its own header: > Trufflehog removed: gitleaks provides sufficient coverage at lower cost. The inline job was left behind when the repo moved to the reusable. It fails and reds the whole workflow, so the repo keeps emitting `ci_activity` notifications even though secret scanning is green. This removes the retired job. Coverage is unchanged — gitleaks in the reusable already covers it. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
1 parent 7cd512b commit 4b06dc7

1 file changed

Lines changed: 0 additions & 10 deletions

File tree

.github/workflows/secret-scanner.yml

Lines changed: 0 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -20,13 +20,3 @@ jobs:
2020
actions: read
2121
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@d135b05bfc647d0c0fbfedc7e80f37ea50f49236
2222
secrets: inherit
23-
trufflehog:
24-
runs-on: ubuntu-latest
25-
steps:
26-
- uses: actions/checkout@v4
27-
with:
28-
fetch-depth: 0
29-
- name: TruffleHog Secret Scan
30-
uses: trufflesecurity/trufflehog@main
31-
with:
32-
extra_args: --only-verified --fail

0 commit comments

Comments
 (0)