diff --git a/.github/workflows/rustScaner.yml b/.github/workflows/rustScaner.yml new file mode 100644 index 0000000..dc9418b --- /dev/null +++ b/.github/workflows/rustScaner.yml @@ -0,0 +1,14 @@ +name: Security audit +on: + push: + paths: + - '**/Cargo.toml' + - '**/Cargo.lock' +jobs: + security_audit: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v1 + - uses: actions-rs/audit-check@v1 + with: + token: ${{ secrets.GITEA_TOKEN }} diff --git a/.github/workflows/scaner.yml b/.github/workflows/scaner.yml index 3fe50e5..d993e16 100644 --- a/.github/workflows/scaner.yml +++ b/.github/workflows/scaner.yml @@ -1,20 +1,13 @@ -name: TruffleHog OSS - -on: - push: - branches: - - master - pull_request: - +name: gitleaks +on: [pull_request, push, workflow_dispatch] jobs: - test: + scan: + name: gitleaks runs-on: ubuntu-latest steps: - - name: Checkout code - uses: actions/checkout@v4 + - uses: actions/checkout@v3 with: fetch-depth: 0 - - name: Secret Scanning - uses: trufflesecurity/trufflehog@main - with: - extra_args: --results=verified,unknown + - uses: gitleaks/gitleaks-action@v1 + env: + GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}