From fb0f95efb52ecf9adb3d6640a005dae4aad5d891 Mon Sep 17 00:00:00 2001 From: Brandon Strege Date: Wed, 23 Sep 2026 13:38:43 -0700 Subject: [PATCH] ci: scan Dependabot PRs without a Gitleaks license Use the pinned MIT-licensed Gitleaks CLI image so the required secret scan runs when Dependabot secrets are unavailable. --- .github/workflows/pr-checks.yml | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/.github/workflows/pr-checks.yml b/.github/workflows/pr-checks.yml index f128c67..4d06704 100644 --- a/.github/workflows/pr-checks.yml +++ b/.github/workflows/pr-checks.yml @@ -44,7 +44,10 @@ jobs: - uses: actions/checkout@v5 with: fetch-depth: 0 - - uses: gitleaks/gitleaks-action@v2 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - GITLEAKS_LICENSE: ${{ secrets.GITLEAKS_LICENSE }} + - name: Scan repository history for secrets + run: >- + docker run --rm + -v "$GITHUB_WORKSPACE:/repo:ro" + -w /repo + ghcr.io/gitleaks/gitleaks:v8.30.1 + detect --source=/repo --redact --no-banner