diff --git a/.github/workflows/gitleaks.yaml b/.github/workflows/gitleaks.yaml new file mode 100644 index 0000000..06716b4 --- /dev/null +++ b/.github/workflows/gitleaks.yaml @@ -0,0 +1,14 @@ +name: gitleaks +on: + push: + branches: [main] + pull_request: +jobs: + scan: + uses: knostic/.github/.github/workflows/gitleaks.yaml@fix/gitleaks-scan-range + with: + event_name: ${{ github.event_name }} + base_sha: ${{ github.event.pull_request.base.sha || '' }} + before_sha: ${{ github.event.before || '' }} + forced: ${{ github.event.forced == true }} + secrets: inherit