eclipse-tractusx / managed-simple-data-exchanger-backend

Apache License 2.0
2 stars 11 forks source link

[Trufflehog Update] Add Trufflehog secret scanning workflow #220

Closed matbmoser closed 1 month ago

matbmoser commented 2 months ago

Description

The GitGuardian secret scanning tool licence is now expired, therefore in order to maintain the Security of the Tractus-X Repositories there will be inforced the TRG-8.03 for all Tractus-X repos.

Incident Ticket

https://github.com/eclipse-tractusx/sig-security/issues/86

Your repository was found in one of our security scans, and it was listed along with other repositories for not contain any of this files:

".github/workflows/trufflehog.yaml"
".github/workflows/trufflehog.yml"
".github/workflows/secrets-scan.yml"

Please read the TRG-8.03 and create the workflow file as soon as posible!

What needs to be done?

Thank you very much for doing the update! 🚀

If there is any question, please let us know,
Your Tractus-X Project Leads 💯

adityagajbhiye9 commented 2 months ago

Requested changes has been been done as per TRG 8.03. https://github.com/eclipse-tractusx/managed-simple-data-exchanger-backend/pull/221