wp-woocommerce-pay/.forgejo/workflows/gitleaks.yml
feibisi e742c09f52
All checks were successful
feicode/ai-security No obvious risky pattern in latest diff
gitleaks 密钥泄露扫描 / gitleaks (push) Successful in -8h1m16s
WordPress 插件 CI / ci (push) Successful in -8h1m15s
fix: gitleaks 改 host 模式,修复 pending 问题
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-02-18 15:35:30 +08:00

31 lines
926 B
YAML

name: gitleaks 密钥泄露扫描
on:
push:
branches: ['*']
pull_request:
branches: ['*']
jobs:
gitleaks:
runs-on: linux-arm64
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Run gitleaks
run: |
if [ "$GITHUB_EVENT_NAME" = "push" ]; then
gitleaks detect --source=. --log-opts="$GITHUB_SHA~1..$GITHUB_SHA" --verbose --exit-code 1 || {
echo "::error::gitleaks 发现了潜在的密钥泄露!请检查上方输出并移除敏感信息。"
exit 1
}
else
gitleaks detect --source=. --verbose --exit-code 1 || {
echo "::error::gitleaks 发现了潜在的密钥泄露!请检查上方输出并移除敏感信息。"
exit 1
}
fi
echo "gitleaks 扫描通过,未发现密钥泄露。"