Skip to content

Secret Scanner

Secret Scanner #211

Workflow file for this run

# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Secret Scanner
on:
pull_request:
push:
branches: [main]
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
actions: read
contents: read
jobs:
scan:
# The pinned reusable (post-standards-#500) needs only `contents: read`:
# its gitleaks job runs a pinned checksum-verified binary and posts no PR
# comments, so the old `pull-requests: write` + `actions: read` caller
# guidance is obsolete (see the PERMISSIONS note in the reusable itself).
# A job-level block REPLACES the workflow-level one for this job.
permissions:
contents: read
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a
secrets: inherit