Skip to content

Commit

Permalink
Merge pull request #21470 from cevich/simpler_to_read_followup
Browse files Browse the repository at this point in the history
Secret-scanning followup fixes
  • Loading branch information
openshift-merge-bot[bot] authored Feb 7, 2024
2 parents 4b90bfb + c5c0799 commit c935f68
Showing 1 changed file with 8 additions and 2 deletions.
10 changes: 8 additions & 2 deletions .github/workflows/scan-secrets.yml
Original file line number Diff line number Diff line change
Expand Up @@ -77,16 +77,22 @@ jobs:
# Provide handy URL for examination of secret leaks for all events that
# trigger this action.

- if: github.event_name == 'synchronize' || github.base_ref == ''
- if: github.event.action == 'synchronize' || github.base_ref == ''
name: Provide URL showing code that needs human eyes (force-push or merge)
shell: bash
run: |
if [[ "$before" =~ ^0000+ ]]; then # Push to new branch (i.e. renovate branch)
echo "Please review newly opened branch for secret-leaks:"
# The event JSON provides the URL we need
jq -r -e '.compare' $GITHUB_EVENT_PATH
return 0
fi
echo "Please review force-push or merged-pr changes for secret-leaks:"
before=$(jq -r -e '.before' $GITHUB_EVENT_PATH)
after=$(jq -r -e '.after' $GITHUB_EVENT_PATH)
echo "https://github.com/${{ github.repository }}/compare/${before}...${after}"
- if: github.event_name == 'opened'
- if: github.event.action == 'opened'
name: Provide URL showing code that needs human eyes (newly opened PR)
shell: bash
run: |
Expand Down

0 comments on commit c935f68

Please sign in to comment.