Skip to content

docs: add Signed commits section to CONTRIBUTING (#71) #200

docs: add Signed commits section to CONTRIBUTING (#71)

docs: add Signed commits section to CONTRIBUTING (#71) #200

# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
name: Secret Scanner
on:
pull_request:
push:
branches: [main]
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
actions: read
contents: read
# Single secret scanner. The standards reusable runs gitleaks (+ a Rust-secrets
# check). An inline TruffleHog job previously lived here, but the reusable
# DELIBERATELY retired TruffleHog as redundant (gitleaks gives sufficient
# coverage at lower cost — see the reusable's header). Re-adding it was
# duplicated work, not extra coverage, so it has been removed. See
# .github/workflows/README.adoc.
jobs:
scan:
# The reusable installs and executes a pinned gitleaks binary directly.
# Since standards#500 it neither comments on PRs nor reads workflow-run
# metadata, so contents: read is the complete permission contract. Keep
# this job-level block explicit: it replaces the workflow-level grant and
# is therefore the cap GitHub applies to the called workflow.
permissions:
contents: read
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540