diff --git a/.github/workflows/public-repo-guard.yml b/.github/workflows/public-repo-guard.yml index 719718a..2b29c00 100644 --- a/.github/workflows/public-repo-guard.yml +++ b/.github/workflows/public-repo-guard.yml @@ -42,7 +42,15 @@ jobs: name: Secrets + content policy runs-on: ubuntu-latest steps: - - uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + with: + # Checkout defaults to persisting the job token for later steps: since v6 it + # lives in a file under $RUNNER_TEMP referenced from .git/config, no longer in + # .git/config itself. It is still a live credential in the job, and this job + # downloads a third-party binary (gitleaks, below) and runs it over the whole + # tree. Nothing here pushes -- the scan is `--no-git` over the working tree -- + # so no step needs authenticated Git; drop it. (zizmor: artipacked) + persist-credentials: false # gitleaks' GitHub Action requires a paid license for organizations; the CLI # itself is MIT-licensed and free. Pin the version AND verify the release