Skip to content

fix(ci): grant callers the permissions their reusable workflows decla… #33

fix(ci): grant callers the permissions their reusable workflows decla…

fix(ci): grant callers the permissions their reusable workflows decla… #33

# SPDX-License-Identifier: MPL-2.0
# Calls the estate's shared secret scanner (gitleaks + rust-secrets +
# shell-secrets). Added because this repository had NO leak scanning at all.
#
# `secrets: inherit` is REQUIRED — without it the gitleaks action's inner
# secrets.GITHUB_TOKEN is empty and the scan silently degrades.
name: "Secret Scanner"
on:
pull_request:
push:
branches: [main, master]
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
secret-scan:
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@571cc734cd69fb846032ec77a662aa8ee4fc32cd
secrets: inherit
permissions:

Check failure on line 21 in .github/workflows/secret-scanner.yml

View workflow run for this annotation

GitHub Actions / .github/workflows/secret-scanner.yml

Invalid workflow file

You have an error in your yaml syntax on line 21
actions: read
contents: read
security-events: write