diff --git a/.gitea/workflows/datadog-secrets-scanning.yml b/.gitea/workflows/datadog-secrets-scanning.yml new file mode 100644 index 0000000..0a06b6d --- /dev/null +++ b/.gitea/workflows/datadog-secrets-scanning.yml @@ -0,0 +1,21 @@ +on: [push] + +name: Datadog Secrets Scanning + +jobs: + static-analysis: + runs-on: ubuntu-latest + name: Datadog Static Analyzer + steps: + - name: Checkout + uses: actions/checkout@v3 + - name: Check code for comitted secrets + id: datadog-static-analysis + uses: DataDog/datadog-static-analyzer-github-action@v1 + with: + dd_api_key: ${{ secrets.DD_API_KEY }} + dd_app_key: ${{ secrets.DD_APP_KEY }} + dd_site: datadoghq.com + secrets_enabled: true + static_analysis_enabled: false + cpu_count: 2