From bd679a6594a64a8a57d630af8a3feaed7bfb7678 Mon Sep 17 00:00:00 2001 From: pedro Date: Fri, 8 May 2026 10:15:24 +0100 Subject: [PATCH] ci: desativar gitleaks temporariamente para testar sonarqube --- .gitea/workflows/deploy.yaml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.gitea/workflows/deploy.yaml b/.gitea/workflows/deploy.yaml index ac98008..6f37170 100644 --- a/.gitea/workflows/deploy.yaml +++ b/.gitea/workflows/deploy.yaml @@ -13,10 +13,10 @@ jobs: fetch-depth: 0 # Necessário para o Gitleaks analisar histórico # 1. SECRET SCANNING (Deteta chaves expostas no histórico e no código) - - name: Gitleaks Scan - run: | - curl -sL https://github.com/gitleaks/gitleaks/releases/download/v8.18.2/gitleaks_8.18.2_linux_x64.tar.gz | tar -xz -C /tmp - /tmp/gitleaks detect --source . --verbose --redact --exit-code 0 + #- name: Gitleaks Scan + # run: | + # curl -sL https://github.com/gitleaks/gitleaks/releases/download/v8.18.2/gitleaks_8.18.2_linux_x64.tar.gz | tar -xz -C /tmp + # /tmp/gitleaks detect --source . --verbose --redact --exit-code 0 # 2. SCA (Software Composition Analysis) - Verifica vulnerabilidades no Nginx - name: Scan Docker Image Vulnerabilities (Trivy)