Skip to content

docs: add Signed commits section to CONTRIBUTING #4

docs: add Signed commits section to CONTRIBUTING

docs: add Signed commits section to CONTRIBUTING #4

Workflow file for this run

# SPDX-License-Identifier: MPL-2.0
# Prevention workflow - scans for hardcoded secrets before they reach main.
#
# Calls the estate's shared secret scanner (gitleaks + rust-secrets +
# shell-secrets). The job key MUST stay `scan`: the estate-wide
# Secret-Scan-Floor ruleset requires the check context `scan / gitleaks`.
#
# No `secrets:` line, deliberately: the reusable references no secrets
# (gitleaks runs as a checksum-verified binary, not gitleaks-action), so
# `secrets: inherit` would only hand it every repo and org secret (CWE-250).
name: Secret Scanner
on:
pull_request:
push:
branches: [main]
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
scan:
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@74d2f66f575246cf6e313ae7775f44df6e097ff2