Skip to content
This repository was archived by the owner on Apr 13, 2023. It is now read-only.

Commit 2bf9edc

Browse files
authored
chore: add git secrets scan (#508)
1 parent 08674d3 commit 2bf9edc

File tree

2 files changed

+22
-0
lines changed

2 files changed

+22
-0
lines changed

.gitallowed

+2
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
# This file matches because of "βrazil nut" (It's silly that git secrets also scans this file, so we cannot write βrazil with a regular "B")
2+
javaHapiValidatorLambda/src/test/resources/testImplementationGuides-r4/us-core/ValueSet-us-core-allergy-substance.json

.github/workflows/build-and-validate.yaml

+20
Original file line numberDiff line numberDiff line change
@@ -33,3 +33,23 @@ jobs:
3333
yarn release
3434
cd ..
3535
yarn release
36+
37+
scan-for-secrets:
38+
name: Scan for secrets
39+
runs-on: ubuntu-latest
40+
steps:
41+
- name: Install Git Secrets
42+
run: |
43+
cd ~
44+
git clone https://github.com/awslabs/git-secrets.git && cd git-secrets
45+
sudo make install
46+
git secrets --register-aws --global
47+
git secrets --add '[aA]pollo|[bB]razil|[cC]oral|[oO]din' --global
48+
git secrets --add 'tt\.amazon\.com|t\.corp\.amazon\.com|issues\.amazon\.com|sim\.amazon\.com|cr\.amazon\.com' --global
49+
- name: Checkout
50+
uses: actions/checkout@v2
51+
- name: Run Git Secrets
52+
run: git secrets --scan
53+
- name: Print remediation message
54+
if: failure()
55+
run: echo "git secrets found potential leaked credentials. If ANY credentials were committed, they MUST be immediately revoked."

0 commit comments

Comments
 (0)