Skip to content

Conversation

@brijeshp56
Copy link
Collaborator

Created trufflehog-scan workflow. Tested below scenarios.

  1. pull request with no secrets.
  2. pull request with secrets.
  3. pull request for exclude option.

Copilot AI review requested due to automatic review settings December 17, 2025 05:52
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a GitHub Actions workflow to scan pull requests for secrets using Trufflehog. The workflow automatically triggers on PR events (opened, edited, reopened, synchronize) and scans for verified and unknown secrets while allowing exclusions via a configuration file.

Key Changes:

  • Added automated secret scanning via Trufflehog on pull request events
  • Configured workflow to scan only changed files between base and head commits
  • Implemented exclusion support via .trufflehog-exclude file

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant