From 719d87d8bd7da6775ccc423d71c4862cfe688ffe Mon Sep 17 00:00:00 2001 From: Sam Erde <20478745+SamErde@users.noreply.github.com> Date: Thu, 1 Oct 2026 12:23:29 -0400 Subject: [PATCH] =?UTF-8?q?=F0=9F=A7=B9=20chore(ci):=20remove=20unreliable?= =?UTF-8?q?=20GitGuardian=20workflow?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .github/workflows/GitGuardian.yml | 46 ------------------------------- 1 file changed, 46 deletions(-) delete mode 100644 .github/workflows/GitGuardian.yml diff --git a/.github/workflows/GitGuardian.yml b/.github/workflows/GitGuardian.yml deleted file mode 100644 index b72684e..0000000 --- a/.github/workflows/GitGuardian.yml +++ /dev/null @@ -1,46 +0,0 @@ -# GitGuardian ---- -name: GitGuardian - -on: - push: - workflow_dispatch: - -permissions: - contents: read - -# No concurrency group is defined on purpose. For push and workflow_dispatch -# runs alike, ggshield selects GITHUB_PUSH_BASE_SHA..GITHUB_SHA, falling back to -# GITHUB_DEFAULT_BRANCH..GITHUB_SHA when the push base is empty and then to -# GITHUB_SHA~1... when that range yields no commits. On the default branch that -# last fallback covers only the head commit, so a run is not guaranteed to -# re-cover an earlier run's commits. GitHub retains a single pending run per -# concurrency group, so a third rapid push would evict the second run even with -# cancel-in-progress: false. Runner time is traded for complete scan coverage. - -jobs: - scanning: - name: GitGuardian Scan - runs-on: ubuntu-latest - timeout-minutes: 20 - permissions: - contents: read - steps: - - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@95d9a5deda9de15063e7595e9719c11c38c90ae2 # v2.13.2 - with: - egress-policy: audit - - - name: Checkout - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0 - with: - fetch-depth: 0 # fetch all history so multiple commits can be scanned - persist-credentials: false # scan-only job; no git write-back is performed - - name: GitGuardian Scan - uses: GitGuardian/ggshield/actions/secret@e4f45829b9b6f4664fe70d2a4dcd307a6833f422 # v1.43.0 - env: - GITHUB_PUSH_BEFORE_SHA: ${{ github.event.before }} - GITHUB_PUSH_BASE_SHA: ${{ github.event.base }} - GITHUB_PULL_BASE_SHA: ${{ github.event.pull_request.base.sha }} - GITHUB_DEFAULT_BRANCH: ${{ github.event.repository.default_branch }} - GITGUARDIAN_API_KEY: ${{ secrets.GITGUARDIAN_API_KEY }}