# https://github.com/trufflesecurity/trufflehog

name: trufflehog secrets scan

on: [pull_request]

jobs:
  trufflehog:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout code
        uses: actions/checkout@v3
        with:
          fetch-depth: 0
      - name: TruffleHog OSS
        uses: trufflesecurity/trufflehog@main
        with:
          path: ./
          base: {% raw %}${{ github.event.repository.default_branch }}{% endraw %}
          head: HEAD
          extra_args: --debug --only-verified