-
Notifications
You must be signed in to change notification settings - Fork 7
Add trufflehog scanner for npm package before publish #1622
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
cad5b8a to
63db736
Compare
|
Website deployed to CF Pages, 👀 preview link https://1285640e.flowzone.pages.dev |
63db736 to
7452ee7
Compare
7452ee7 to
cb9379e
Compare
flowzone.yml
Outdated
|
|
||
| env: | ||
| # renovate: datasource=github-releases depName=trufflesecurity/trufflehog | ||
| TRUFFLEHOG_VERSION: "3.91.0" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Move these envs from the job to the step, as we shouldn't use global envs unless required for multiple steps.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
docker image https://balena.fibery.io/Work/Project/Scan-flowzone-build-artefacts-for-leaked-secrets-1856 Change-type: minor Signed-off-by: fisehara <harald@balena.io>
cabe805 to
67e7c41
Compare
https://balena.fibery.io/Work/Project/Scan-flowzone-build-artefacts-for-leaked-secrets-1856 Change-type: minor Signed-off-by: fisehara <harald@balena.io>
67e7c41 to
8f9626e
Compare
klutchell
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Do we know how to exclude npm test fixture directories to avoid the issues we saw with the docker scanning?
https://balena.fibery.io/Work/Project/Scan-flowzone-build-artefacts-for-leaked-secrets-1856
Change-type: minor