name: Security Checks on: pull_request: push: branches: [ main ] jobs: sca-deps: # Dependency & container scan runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: aquasecurity/trivy-action@0.20.0 with: scan-type: 'fs' format: 'table' severity: 'CRITICAL,HIGH' ignore-unfixed: true secrets-gitleaks: # Secrets exposure runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 with: fetch-depth: 0 # Fetch full history for gitleaks - uses: gitleaks/gitleaks-action@v2 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITLEAKS_LICENSE: ${{ secrets.GITLEAKS_LICENSE }} with: config-path: .gitleaks.toml # Optional, if you have a custom config