Repository navigation
chore(deps): bump pyjwt from 2.13.0 to 2.15.0 in /apps/api/requirements #93
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # woven: gitleaks — scan for committed secrets on every PR and on push to main. Belt-and-braces | |
| # with GitHub-native secret scanning + push protection (repo setting, enabled alongside this). | |
| # gitleaks-action v2 is free for personal repos (no GITLEAKS_LICENSE needed for aRustyDev). | |
| # Tracks plane-7fn.4.9 (§H). | |
| name: Secret scan (gitleaks) | |
| on: | |
| pull_request: | |
| push: | |
| branches: [main] | |
| permissions: | |
| contents: read | |
| jobs: | |
| gitleaks: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 | |
| with: | |
| fetch-depth: 0 # full history so PR/push commit ranges are scannable | |
| - name: gitleaks | |
| uses: gitleaks/gitleaks-action@ff98106e4c7b2bc287b24eaf42907196329070c7 # v2.3.9 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} |