Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Trufflehog Update] Add Trufflehog secret scanning workflow #19

Open
5 tasks
matbmoser opened this issue Sep 18, 2024 · 0 comments
Open
5 tasks

[Trufflehog Update] Add Trufflehog secret scanning workflow #19

matbmoser opened this issue Sep 18, 2024 · 0 comments
Labels
bug Something isn't working github_actions Pull requests that update GitHub Actions code

Comments

@matbmoser
Copy link

matbmoser commented Sep 18, 2024

Description

The GitGuardian secret scanning tool licence is now expired, therefore in order to maintain the Security of the Tractus-X Repositories there will be inforced the TRG-8.03 for all Tractus-X repos.

Main ticket

eclipse-tractusx/sig-security#86

What needs to be done?

  • Add the Trufflehog workflow like described in TRG-8.03 to the /.github/workflows folder
  • Remove all references to GitGuardian from documentation
  • Create a PR and Merge it to main
  • As committer: revise if any secrets were found in the scan (in security tab)
  • Close this ticket

Thank you very much for doing the update! 🚀
If there is any question, please let us know,

Your Tractus-X Project Leads 💯

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working github_actions Pull requests that update GitHub Actions code
Projects
None yet
Development

No branches or pull requests

1 participant