Skip to content

ci: add dependabot.yml (#10) #10

ci: add dependabot.yml (#10)

ci: add dependabot.yml (#10) #10

Workflow file for this run

name: Secret scan
# This repo is public. These jobs answer "has a credential reached the
# public internet," on the push itself, not on some later PR review --
# there is no local pre-commit hook here yet to catch it first.
#
# Why no paths: filter, though it would cut run count: gitleaks and
# trufflehog both scan FULL history (fetch-depth: 0) on every run, so
# filtering by one push's changed files would skip a whole-history scan
# just because the newest commit only touched a README. A path allowlist
# would also gate the scan on the same "files we thought about" list whose
# gaps are the actual leak path.
#
# No sops/encrypted-secrets job here (unlike dotfiles/symphony): this repo
# manages no encrypted secrets. Add one if that changes.
on:
push:
branches: ['**']
workflow_dispatch:
schedule:
# Weekly re-scan of unchanged history. Not redundant: trufflehog ships
# new detectors continuously, so a commit that was clean last month can
# be flagged this month by a detector that didn't exist then.
- cron: "41 9 * * 1"
# A session that pushes four times in two minutes only needs the newest
# commit scanned; superseded runs are cancelled. Scheduled runs are exempt
# -- the weekly sweep of unchanged history is the one run that must not be
# cancelled by an unrelated push landing on the same ref. That requires a
# separate group per event kind (CodeRabbit, 2026-09-05): the schedule fires
# against main, so a push to main used to share gitleaks' group with an
# in-progress scheduled run, and cancel-in-progress on the NEW (push) run is
# what cancels the OLD (scheduled) one -- the scheduled run's own
# cancel-in-progress never got a say.
concurrency:
group: secret-scan-${{ github.ref }}-${{ github.event_name == 'push' && 'push' || github.run_id }}
cancel-in-progress: ${{ github.event_name == 'push' }}
permissions:
contents: read
jobs:
# gitleaks (full history) + trufflehog (verified-live only), both shared
# with dotfiles/symphony/space-weather via mark-brannan/.github -- see
# that repo's secret-scan.yml for what each job does and why. This repo
# has no .gitleaks.toml, so no gitleaks-config input is passed.
secret-scan:
permissions:
contents: read
# @main, deliberately -- same-owner trust, matching every other caller
# of a mark-brannan/.github workflow. CodeRabbit flagged this as
# unpinned (2026-09-05, zizmor's unpinned-uses); considered and
# reverted (2026-09-05): the threat that lint guards against is a
# compromised upstream *maintainer*, which doesn't apply when the
# upstream is your own repo. Pinning would only buy protection
# against mistakes in the shared workflow, at the cost of a manual
# pin-bump PR per caller for every future fix.
uses: mark-brannan/.github/.github/workflows/secret-scan.yml@main