Skip to content

restyle the badge

restyle the badge #7

Workflow file for this run

name: Secret Scanning
on:
push:
branches: ["**"]
pull_request:
schedule:
- cron: "0 6 * * 1" # weekly, Mondays 06:00 UTC
workflow_dispatch:
permissions:
contents: read
security-events: write
jobs:
gitleaks:
name: Gitleaks Scan
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0 # scan full history
- name: Run Gitleaks
uses: zricethezav/gitleaks-action@v2
with:
args: detect --source . --report-format sarif --report-path gitleaks.sarif --redact
- name: Upload SARIF to Security tab
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: gitleaks.sarif
- name: Upload report artifact
if: always()
uses: actions/upload-artifact@v4
with:
name: gitleaks-report
path: gitleaks.sarif