diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 1e7d200f..af798942 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -20,6 +20,17 @@ jobs: - name: checking syntax of shell script run: bash -c 'shopt -s globstar nullglob; shellcheck **/*.{sh,ksh,bash}' || true + gitleaks-scan: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v3 + with: + fetch-depth: 0 + - name: Run GitLeaks + run: | + wget https://github.com/gitleaks/gitleaks/releases/download/v8.18.2/gitleaks_8.18.2_linux_x64.tar.gz && \ + tar -zxvf gitleaks_8.18.2_linux_x64.tar.gz && \ + sudo mv gitleaks /usr/local/bin && gitleaks detect --source . -v changes: runs-on: ubuntu-latest