Skip to content

Commit 36c48a8

Browse files
committed
ci: redistribute canonical secret-scanner.yml (concurrency-cancel guard) (Refs hyperpolymath/standards#122)
1 parent 44440fb commit 36c48a8

1 file changed

Lines changed: 11 additions & 3 deletions

File tree

‎.github/workflows/secret-scanner.yml‎

Lines changed: 11 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# SPDX-License-Identifier: PMPL-1.0-or-later
1+
# SPDX-License-Identifier: PMPL-1.0
22
# Prevention workflow - scans for hardcoded secrets before they reach main
33
name: Secret Scanner
44

@@ -7,6 +7,14 @@ on:
77
push:
88
branches: [main]
99

10+
# Estate guardrail: cancel superseded runs so re-pushes / rebased PR
11+
# updates do not pile up queued runs against the shared account-wide
12+
# Actions concurrency pool. Applied only to read-only check workflows
13+
# (no publish/mutation), so cancelling a superseded run is always safe.
14+
concurrency:
15+
group: ${{ github.workflow }}-${{ github.ref }}
16+
cancel-in-progress: true
17+
1018
permissions:
1119
contents: read
1220

@@ -19,7 +27,7 @@ jobs:
1927
fetch-depth: 0 # Full history for scanning
2028

2129
- name: TruffleHog Secret Scan
22-
uses: trufflesecurity/trufflehog@8a8ef8526528d8a4ff3e2c90be08e25ef8efbd9b # v3
30+
uses: trufflesecurity/trufflehog@6c05c4a00b91aa542267d8e32a8254774799d68d # v3
2331
with:
2432
# The v3 action injects --fail automatically on pull_request events.
2533
# Passing --fail here triggers "flag 'fail' cannot be repeated".
@@ -70,4 +78,4 @@ jobs:
7078
if [ $found -eq 1 ]; then
7179
echo "::error::Potential hardcoded secrets detected. Use environment variables instead."
7280
exit 1
73-
fi
81+
fi

0 commit comments

Comments
 (0)