Add TruffleHog secret scan workflow #1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| ###################################################################### | |
| # @CCOSTAN - Follow Me on X | |
| # For more info visit https://www.vcloudinfo.com/click-here | |
| # Original Repo : https://github.com/CCOSTAN/Home-AssistantConfig | |
| # ------------------------------------------------------------------- | |
| # Secret Scan Workflow - TruffleHog credential leak detection. | |
| # Runs verified-only secret scanning on pull requests, master pushes, | |
| # and manual dispatch without adding local commit-hook friction. | |
| # ------------------------------------------------------------------- | |
| ###################################################################### | |
| name: Secret Scan | |
| on: | |
| pull_request: | |
| push: | |
| branches: ["master"] | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| jobs: | |
| trufflehog: | |
| name: TruffleHog | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Check out repository | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - name: Scan for verified secrets | |
| uses: trufflesecurity/trufflehog@v3.95.3 | |
| with: | |
| version: v3.95.3 | |
| extra_args: --results=verified --force-skip-binaries --force-skip-archives |