Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Trufflehog Update] Add Trufflehog secret scanning workflow #351

Open
2 of 5 tasks
matbmoser opened this issue Sep 18, 2024 · 0 comments
Open
2 of 5 tasks

[Trufflehog Update] Add Trufflehog secret scanning workflow #351

matbmoser opened this issue Sep 18, 2024 · 0 comments

Comments

@matbmoser
Copy link

matbmoser commented Sep 18, 2024

Description

The GitGuardian secret scanning tool licence is now expired, therefore in order to maintain the Security of the Tractus-X Repositories there will be inforced the TRG-8.03 for all Tractus-X repos.

Incident Ticket

eclipse-tractusx/sig-security#86

Your repository was found in one of our security scans, and it was listed along with other repositories for not contain any of this files:

".github/workflows/trufflehog.yaml"
".github/workflows/trufflehog.yml"
".github/workflows/secrets-scan.yml"

Please read the TRG-8.03 and create the workflow file as soon as posible!

What needs to be done?

  • Add the Trufflehog workflow like described in TRG-8.03 to the /.github/workflows folder
  • Remove all references to GitGuardian from documentation
  • Create a PR and Merge it to main
  • As committer: revise if any secrets were found in the scan (in the security tab)
  • Close this ticket

Thank you very much for doing the update! 🚀

If there is any question, please let us know,
Your Tractus-X Project Leads 💯

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant