Merge pull request 'ci: scan range histories' (#3) from ci/gitleaks-branch-commits into develop
Push -> develop / Build Docker image (push) Successful in 12s
Push -> develop / Deploy (push) Successful in 3s
Push -> develop / Notify on result (push) Successful in 0s

Reviewed-on: #3
This commit was merged in pull request #3.
This commit is contained in:
2026-06-23 02:43:43 +00:00
+5 -1
View File
@@ -33,7 +33,11 @@ jobs:
mv gitleaks /usr/local/bin/gitleaks
- name: Run secret scan
run: gitleaks detect --source . --exit-code 1 --redact --verbose --log-level debug
# Scan only the commits this PR introduces (base..head), not the whole history.
run: |
gitleaks detect --source . \
--log-opts="${{ github.event.pull_request.base.sha }}..${{ github.event.pull_request.head.sha }}" \
--exit-code 1 --redact --verbose --log-level debug
# ── 2. CVE scan ───────────────────────────────────────────────────────────────
trivy: