diff --git a/scan-secrets.yml b/scan-secrets.yml new file mode 100644 index 0000000..fe001d0 --- /dev/null +++ b/scan-secrets.yml @@ -0,0 +1,46 @@ +name: Scan for Secrets + +on: + push: + branches: + - main + - develop + pull_request: + branches: + - main + - develop + +jobs: + scan-secrets: + name: Run TruffleHog and git-secrets + runs-on: ubuntu-latest + steps: + - name: Checkout code + uses: actions/checkout@v3 + + - name: Set up Python + uses: actions/setup-python@v4 + with: + python-version: '3.x' + + - name: Install TruffleHog + run: | + pip install truffleHog + + - name: Scan for secrets with TruffleHog + run: | + truffleHog --regex --entropy=True . + + - name: Install git-secrets + run: | + sudo apt-get update + sudo apt-get install -y git-secrets + + - name: Initialize git-secrets + run: | + git secrets --install + git secrets --register-aws # AWS anahtarlarını taramak için + + - name: Scan for secrets with git-secrets + run: | + git secrets --scan