eclipse-tractusx / sldt-discovery-finder

Apache License 2.0
1 stars 5 forks source link

chore: Added trufflehog secret scanning tool #162

Closed RoKrish14 closed 1 month ago

RoKrish14 commented 2 months ago

Description

This PR introduces TruffleHog as a new open source tool for secret scanning to be used alongside native Github Secret scanning. This is being enforced as a replacement to the existing GitGuardian (commercial) tool.

Update trg-8-03.md

Pre-review checks

Please ensure to do as many of the following checks as possible, before asking for committer review:

sonarcloud[bot] commented 2 months ago

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarCloud

RoKrish14 commented 1 month ago

I would like know if there are any blockers to review and merge this PR.

agg3fe commented 1 month ago

I would like know if there are any blockers to review and merge this PR.

Hi Rohan, no blockers. I will merge it. Will do the same for other repositories also. Do I need to make any changes here for other repos?

RoKrish14 commented 1 month ago

I have created PR in other repo's too. Feel free to make updates if needed. Nothing to be done here.

agg3fe commented 1 month ago

I have created PR in other repo's too. Feel free to make updates if needed. Nothing to be done here.

Actually I can't find the same PRs for below repos, could you please help me if you have raised for these repos also: https://github.com/eclipse-tractusx/sldt-digital-twin-registry/pulls https://github.com/eclipse-tractusx/sldt-bpn-discovery/pulls https://github.com/eclipse-tractusx/sldt-semantic-hub/pulls

RoKrish14 commented 1 month ago

Sadly, none of these. I had randomly chosen few repo's so that every other product lines can be smoothly onboarded. For SLDT, I chose only one repo to present the PR which can stand as a reference.