Add Pipelock agent security scan to CI (#1049)

* Add Pipelock agent security scan to CI

Scans PR diffs for leaked secrets and agent security risks.
Zero config, runs on every PR to main.

* Retrigger CI (v1 action tag now available)

* Harden checkout: persist-credentials false

Pipelock only reads local git history for diff scanning,
no auth token needed in .git/config.
This commit is contained in:
LPW
2026-02-23 07:33:36 -05:00
committed by GitHub
parent ad3087f1dd
commit 0ddca461fc

24
.github/workflows/pipelock.yml vendored Normal file
View File

@@ -0,0 +1,24 @@
name: Pipelock Security Scan
on:
pull_request:
branches: [main]
permissions:
contents: read
jobs:
security-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
persist-credentials: false
- name: Pipelock Scan
uses: luckyPipewrench/pipelock@v1
with:
scan-diff: 'true'
fail-on-findings: 'true'
test-vectors: 'false'