From 79abc9772d1054eae07b422ebe706e37fe567626 Mon Sep 17 00:00:00 2001 From: Rohan Krishnamurthy Date: Tue, 30 Jul 2024 10:23:08 +0200 Subject: [PATCH 1/2] Create trufflehog.yml --- .github/workflows/trufflehog.yml | 40 ++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) create mode 100644 .github/workflows/trufflehog.yml diff --git a/.github/workflows/trufflehog.yml b/.github/workflows/trufflehog.yml new file mode 100644 index 00000000..4428a876 --- /dev/null +++ b/.github/workflows/trufflehog.yml @@ -0,0 +1,40 @@ +name: "TruffleHog" + +on: + push: + branches: [ main ] + pull_request: + + schedule: + - cron: "0 0 * * *" # Once a day + +permissions: + actions: read + contents: read + security-events: write + id-token: write + issues: write + +jobs: + ScanSecrets: + name: Scan secrets + runs-on: ubuntu-latest + steps: + - name: Checkout Repository + uses: actions/checkout@v3 + with: + fetch-depth: 0 # Ensure full clone for pull request workflows + ref: ${{ github.head_ref }} # Fetch specific branch/commit for pull requests + + - name: TruffleHog OSS + id: trufflehog + uses: trufflesecurity/trufflehog@8a8ef8526527dd5f5d731d8e74843c121777b82d #v3.80.2 + continue-on-error: true + with: + path: ./ # Scan the entire repository + base: "${{ github.event.repository.default_branch }}" # Set base branch for comparison (pull requests) + extra_args: --filter-entropy=4 --results=verified,unknown --debug + + - name: Scan Results Status + if: steps.trufflehog.outcome == 'failure' + run: exit 1 # Set workflow run to failure if TruffleHog finds secrets From f29a75f6997725d03e8739f8d51f7d826edaf135 Mon Sep 17 00:00:00 2001 From: Tom Meyer Date: Wed, 7 Aug 2024 23:41:24 -0700 Subject: [PATCH 2/2] Apply suggestions from code review fix: run job on pr --- .github/workflows/trufflehog.yml | 25 +++++++++++++++++++++++-- 1 file changed, 23 insertions(+), 2 deletions(-) diff --git a/.github/workflows/trufflehog.yml b/.github/workflows/trufflehog.yml index 4428a876..77e531f0 100644 --- a/.github/workflows/trufflehog.yml +++ b/.github/workflows/trufflehog.yml @@ -1,12 +1,33 @@ +# +# Copyright (c) 2024 Contributors to the Eclipse Foundation +# +# See the NOTICE file(s) distributed with this work for additional +# information regarding copyright ownership. +# +# This program and the accompanying materials are made available under the +# terms of the Apache License, Version 2.0 which is available at +# https://www.apache.org/licenses/LICENSE-2.0. +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT +# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the +# License for the specific language governing permissions and limitations +# under the License. +# +# SPDX-License-Identifier: Apache-2.0 +# + name: "TruffleHog" on: push: - branches: [ main ] + branches: ["main"] pull_request: - + # The branches below must be a subset of the branches above + branches: ["main"] schedule: - cron: "0 0 * * *" # Once a day + workflow_dispatch: permissions: actions: read