Fix SAST TruffleHog failure on main branch pushes #28
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The SAST security workflow was failing on main branch pushes with the error:
This occurs because TruffleHog's diff-based scanning compares
base
andhead
commits, but on main branch pushes these are often identical. The tool expects to compare different commits to detect newly introduced secrets.Solution
Added a conditional to skip TruffleHog's diff scan specifically for main branch push events:
Impact
This change:
Security coverage remains comprehensive since secrets are primarily introduced via pull requests, where TruffleHog continues to provide diff-based scanning.
Fixes #27.
✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.