Files
trufflehog/.github/workflows/release-bot.yml
renovate[bot]Cursorrenovate[bot] <29139614+renovate[bot]@users.noreply.github.com>Bryan Beverly
076331ca6b Update github-actions (#5036)
* Update github-actions

* Match scripts/lint.sh golangci-lint version to CI workflow

Local linting pinned v2.11.4 while the workflow now pins v2.12.2, so
goconst, dupl, and gosec results could diverge between local and CI runs.

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Bryan Beverly <[email protected]>
Co-authored-by: Cursor <[email protected]>
2026-07-31 00:50:23 -07:00

37 lines
1.1 KiB
YAML

name: Run release bot
on:
release:
types: [published]
permissions: {}
jobs:
run:
if: ${{ github.repository == 'trufflesecurity/trufflehog' }}
runs-on: ubuntu-latest
steps:
- name: Login to GCP
id: auth
uses: "google-github-actions/auth@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093" # v3
with:
credentials_json: ${{ secrets.GCP_SA_TRUFFLE_RELEASE_BOT }}
- name: Login to GAR
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4
with:
registry: us-central1-docker.pkg.dev
username: _json_key
password: ${{ secrets.GCP_SA_TRUFFLE_RELEASE_BOT }}
- name: Run release bot
env:
RELEASE_TAG: ${{ github.event.release.tag_name }}
run: |
docker run \
-e GOOGLE_APPLICATION_CREDENTIALS=/tmp/keys/GCP_SA_TRUFFLE_RELEASE_BOT.json \
-v ${{ steps.auth.outputs.credentials_file_path }}:/tmp/keys/GCP_SA_TRUFFLE_RELEASE_BOT.json:ro \
us-central1-docker.pkg.dev/truffle-release-bot/releases/bot:latest \
--repository trufflehog "$RELEASE_TAG"