diff --git a/.github/workflows/quality.yml b/.github/workflows/quality.yml index 5c6536b1..68a2ebcb 100644 --- a/.github/workflows/quality.yml +++ b/.github/workflows/quality.yml @@ -19,7 +19,7 @@ jobs: find . -type f -perm /111 -name "*.sh" | head -10 || true - name: Check for secrets - uses: trufflesecurity/trufflehog@6c05c4a00b91aa542267d8e32a8254774799d68d # main + uses: trufflesecurity/trufflehog@586f66d7886cd0b037c7c245d4a6e34ef357ab10 # main with: path: ./ base: ${{ github.event.pull_request.base.sha || github.event.before }} diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index b3cb8c4e..e558ec70 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -23,6 +23,6 @@ jobs: fetch-depth: 0 - name: Run TruffleHog - uses: trufflesecurity/trufflehog@6c05c4a00b91aa542267d8e32a8254774799d68d # main + uses: trufflesecurity/trufflehog@586f66d7886cd0b037c7c245d4a6e34ef357ab10 # main with: extra_args: --only-verified