diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 7a3dfe1..c5b5c30 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -22,6 +22,11 @@ jobs: uses: actions/checkout@v6 with: fetch-depth: 0 + # MegaLinter扫描步骤 + - name: MegaLinter + uses: oxsecurity/megalinter@v9.3.0 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} # TruffleHog OSS 扫描步骤 # 使用 TruffleHog 工具扫描代码库中的敏感信息泄露,如API密钥、密码等 # 该步骤会比较基础分支和当前提交之间的差异,检测新增内容中是否包含敏感数据