diff --git a/.gitea/workflows/secrets-scan.yml b/.gitea/workflows/secrets-scan.yml new file mode 100644 index 0000000..71ff0e2 --- /dev/null +++ b/.gitea/workflows/secrets-scan.yml @@ -0,0 +1,19 @@ +name: Secrets Scan + +on: + push: + branches: [main] + pull_request: + branches: [main] + +jobs: + secrets-scan: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - name: Secrets Scan + uses: trufflesecurity/trufflehog@main + with: + path: . + base: main + head: HEAD