Skip to content

🔒 security(ci): harden workflow credentials, permissions, and executi… #164

🔒 security(ci): harden workflow credentials, permissions, and executi…

🔒 security(ci): harden workflow credentials, permissions, and executi… #164

Workflow file for this run

# GitGuardian
---
name: GitGuardian
on:
push:
workflow_dispatch:
permissions:
contents: read
# Serialize runs per ref without cancelling: every pushed commit range must still
# be scanned, so queued runs are allowed to finish instead of being superseded.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: false
jobs:
scanning:
name: GitGuardian Scan
runs-on: ubuntu-latest
timeout-minutes: 20
permissions:
contents: read
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@95d9a5deda9de15063e7595e9719c11c38c90ae2 # v2.13.2
with:
egress-policy: audit
- name: Checkout
uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
with:
fetch-depth: 0 # fetch all history so multiple commits can be scanned
persist-credentials: false # scan-only job; no git write-back is performed
- name: GitGuardian Scan
uses: GitGuardian/ggshield/actions/secret@e4f45829b9b6f4664fe70d2a4dcd307a6833f422 # v1.43.0
env:
GITHUB_PUSH_BEFORE_SHA: ${{ github.event.before }}
GITHUB_PUSH_BASE_SHA: ${{ github.event.base }}
GITHUB_PULL_BASE_SHA: ${{ github.event.pull_request.base.sha }}
GITHUB_DEFAULT_BRANCH: ${{ github.event.repository.default_branch }}
GITGUARDIAN_API_KEY: ${{ secrets.GITGUARDIAN_API_KEY }}