mirror of
https://github.com/we-promise/sure.git
synced 2026-04-20 04:24:06 +00:00
Add Pipelock agent security scan to CI (#1049)
* Add Pipelock agent security scan to CI Scans PR diffs for leaked secrets and agent security risks. Zero config, runs on every PR to main. * Retrigger CI (v1 action tag now available) * Harden checkout: persist-credentials false Pipelock only reads local git history for diff scanning, no auth token needed in .git/config.
This commit is contained in:
24
.github/workflows/pipelock.yml
vendored
Normal file
24
.github/workflows/pipelock.yml
vendored
Normal file
@@ -0,0 +1,24 @@
|
|||||||
|
name: Pipelock Security Scan
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
branches: [main]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
security-scan:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
persist-credentials: false
|
||||||
|
|
||||||
|
- name: Pipelock Scan
|
||||||
|
uses: luckyPipewrench/pipelock@v1
|
||||||
|
with:
|
||||||
|
scan-diff: 'true'
|
||||||
|
fail-on-findings: 'true'
|
||||||
|
test-vectors: 'false'
|
||||||
Reference in New Issue
Block a user