Skip to content

Commit

Permalink
build: TRG-8-03 enable TruffleHog secrets scan
Browse files Browse the repository at this point in the history
  • Loading branch information
ndr-brt committed Aug 8, 2024
1 parent 130c6ed commit e0409a5
Show file tree
Hide file tree
Showing 3 changed files with 93 additions and 3 deletions.
35 changes: 35 additions & 0 deletions .github/workflows/dash-scan.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
name: "3rd Party dependency check (Eclipse Dash)"

on:
workflow_dispatch:
push:
branches:
- main
pull_request:
branches:
- main

permissions:
contents: write

jobs:
check-dependencies:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- name: generate dependency list
run: ./gradlew allDependencies | grep -Poh "(?<=\s)[\w.-]+:[\w.-]+:[^:\s\[\]]+" | sort | uniq > dependency-list

- name: Run dash
id: run-dash
uses: eclipse-tractusx/sig-infra/.github/actions/run-dash@main
with:
dash_input: dependency-list
dependencies_file: DEPENDENCIES
fail_on_out_of_date: true
fail_on_rejected: true
fail_on_restricted: false

- if: failure()
run: cat DEPENDENCIES
58 changes: 58 additions & 0 deletions .github/workflows/secrets-scan.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
#################################################################################
# Copyright (c) 2024 Contributors to the Eclipse Foundation
#
# See the NOTICE file(s) distributed with this work for additional
# information regarding copyright ownership.
#
# This program and the accompanying materials are made available under the
# terms of the Apache License, Version 2.0 which is available at
# https://www.apache.org/licenses/LICENSE-2.0.
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
# License for the specific language governing permissions and limitations
# under the License.
#
# SPDX-License-Identifier: Apache-2.0
#################################################################################


name: "Secrets scan: TruffleHog"

on:
push:
branches: [ main ]
pull_request:
schedule:
- cron: "0 0 * * *" # Once a day

permissions:
actions: read
contents: read
security-events: write
id-token: write
issues: write

jobs:
ScanSecrets:
name: Scan secrets
runs-on: ubuntu-latest
steps:
- name: Checkout Repository
uses: actions/checkout@v4
with:
fetch-depth: 0 # Ensure full clone for pull request workflows

- name: TruffleHog OSS
id: trufflehog
uses: trufflesecurity/trufflehog@main
continue-on-error: true
with:
path: ./ # Scan the entire repository
base: "${{ github.event.repository.default_branch }}" # Set base branch for comparison (pull requests)
extra_args: --filter-entropy=4 --results=verified,unknown --debug

- name: Scan Results Status
if: steps.trufflehog.outcome == 'failure'
run: exit 1 # Set workflow run to failure if TruffleHog finds secrets
3 changes: 0 additions & 3 deletions .github/workflows/verify.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -64,9 +64,6 @@ jobs:
exit 1
fi
verify-dependencies:
uses: eclipse-edc/.github/.github/workflows/dependency-check.yml@main

verify-formatting:
runs-on: ubuntu-latest
steps:
Expand Down

0 comments on commit e0409a5

Please sign in to comment.