Merge pull request #8 from Molecule-AI/chore/enroll-secret-scan

chore(ci): enroll in org-wide secret-scan reusable workflow (Molecule-AI/molecule-core#2109)
This commit is contained in:
Hongming Wang 2026-04-29 13:48:42 -07:00 committed by GitHub
commit 1dca06bd12
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

22
.github/workflows/secret-scan.yml vendored Normal file
View File

@ -0,0 +1,22 @@
name: Secret scan
# Calls the canonical reusable workflow in molecule-core. Defense
# against the #2090-class leak (a hosted-agent commit slipping a
# credential-shaped string into a PR). Pattern set lives in
# molecule-core so we do not maintain a parallel copy here.
#
# Pinned to @staging because that is the active default branch on the
# upstream repo (main lags behind via the staging-promotion workflow).
# Updates ride along automatically as the upstream regex set evolves.
on:
pull_request:
types: [opened, synchronize, reopened]
push:
branches: [main, staging, master]
merge_group:
types: [checks_requested]
jobs:
secret-scan:
uses: Molecule-AI/molecule-core/.github/workflows/secret-scan.yml@staging