ci: add dependabot.yml (#10) #10
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Secret scan | |
| # This repo is public. These jobs answer "has a credential reached the | |
| # public internet," on the push itself, not on some later PR review -- | |
| # there is no local pre-commit hook here yet to catch it first. | |
| # | |
| # Why no paths: filter, though it would cut run count: gitleaks and | |
| # trufflehog both scan FULL history (fetch-depth: 0) on every run, so | |
| # filtering by one push's changed files would skip a whole-history scan | |
| # just because the newest commit only touched a README. A path allowlist | |
| # would also gate the scan on the same "files we thought about" list whose | |
| # gaps are the actual leak path. | |
| # | |
| # No sops/encrypted-secrets job here (unlike dotfiles/symphony): this repo | |
| # manages no encrypted secrets. Add one if that changes. | |
| on: | |
| push: | |
| branches: ['**'] | |
| workflow_dispatch: | |
| schedule: | |
| # Weekly re-scan of unchanged history. Not redundant: trufflehog ships | |
| # new detectors continuously, so a commit that was clean last month can | |
| # be flagged this month by a detector that didn't exist then. | |
| - cron: "41 9 * * 1" | |
| # A session that pushes four times in two minutes only needs the newest | |
| # commit scanned; superseded runs are cancelled. Scheduled runs are exempt | |
| # -- the weekly sweep of unchanged history is the one run that must not be | |
| # cancelled by an unrelated push landing on the same ref. That requires a | |
| # separate group per event kind (CodeRabbit, 2026-09-05): the schedule fires | |
| # against main, so a push to main used to share gitleaks' group with an | |
| # in-progress scheduled run, and cancel-in-progress on the NEW (push) run is | |
| # what cancels the OLD (scheduled) one -- the scheduled run's own | |
| # cancel-in-progress never got a say. | |
| concurrency: | |
| group: secret-scan-${{ github.ref }}-${{ github.event_name == 'push' && 'push' || github.run_id }} | |
| cancel-in-progress: ${{ github.event_name == 'push' }} | |
| permissions: | |
| contents: read | |
| jobs: | |
| # gitleaks (full history) + trufflehog (verified-live only), both shared | |
| # with dotfiles/symphony/space-weather via mark-brannan/.github -- see | |
| # that repo's secret-scan.yml for what each job does and why. This repo | |
| # has no .gitleaks.toml, so no gitleaks-config input is passed. | |
| secret-scan: | |
| permissions: | |
| contents: read | |
| # @main, deliberately -- same-owner trust, matching every other caller | |
| # of a mark-brannan/.github workflow. CodeRabbit flagged this as | |
| # unpinned (2026-09-05, zizmor's unpinned-uses); considered and | |
| # reverted (2026-09-05): the threat that lint guards against is a | |
| # compromised upstream *maintainer*, which doesn't apply when the | |
| # upstream is your own repo. Pinning would only buy protection | |
| # against mistakes in the shared workflow, at the cost of a manual | |
| # pin-bump PR per caller for every future fix. | |
| uses: mark-brannan/.github/.github/workflows/secret-scan.yml@main |