Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 17 additions & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -76,12 +76,26 @@ jobs:
fetch-depth: 0

- name: Scan for committed secrets
# Pinned to a release tag. Never use @master or @main for a third-party
# action: a mutable ref is a remote-code-execution path into CI.
# Dependabot keeps this pin current (.github/dependabot.yml).
# Two pins, not one. `uses:` pins the composite wrapper; `version:` pins
# the scanner the wrapper actually runs. The action's `version` input
# defaults to `latest`, so without the second pin this step downloads
# ghcr.io/trufflesecurity/trufflehog:latest on every run — the code that
# decides whether the job passes would be a mutable ref, which is the
# remote-code-execution path this comment used to claim was closed. It
# also meant an upstream change to exit-code behaviour reached this
# workflow with no pull request. Keep the two versions equal.
#
# Dependabot updates the `uses:` ref (.github/dependabot.yml); it does
# not know about `version:`. Update both together. See issue #14.
#
# Mind the prefix: the action is tagged `v3.96.0`, the container image is
# tagged `3.96.0`. Passing the `v` form here fails the job with
# `manifest unknown` and exit 125 — noisy, but fail-closed, which is the
# right direction for a security gate.
uses: trufflesecurity/trufflehog@v3.96.0
with:
path: ./
version: 3.96.0
# --only-verified keeps this a blocking gate rather than a noise
# generator: it fails on credentials TruffleHog can actively confirm
# are live. Unverified matches are deliberately not fatal, because
Expand Down