Skip to content

docs: add Signed commits section to CONTRIBUTING #223

docs: add Signed commits section to CONTRIBUTING

docs: add Signed commits section to CONTRIBUTING #223

Workflow file for this run

# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
name: Secret Scanner
on:
pull_request:
push:
branches: [main]
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
actions: read
contents: read
jobs:
scan:
# The reusable (post-standards-#500) needs only `contents: read` for its
# own scans: its gitleaks job runs a pinned checksum-verified binary and
# posts no PR comments, so the old `pull-requests: write` caller guidance
# is obsolete. This job-level block REPLACES the workflow-level one for
# this job — it is the cap GitHub applies to the called workflow.
permissions:
contents: read
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540
# `secrets: inherit` is required by the callee's contract
# (secret-scanner-reusable.yml@da2c748): without it the inner
# `secrets.GITHUB_TOKEN` reference resolves empty and gitleaks falls back
# to anonymous mode (rate-limited; misses some PRs).
secrets: inherit