diff --git a/Taskfile.yaml b/Taskfile.yaml index 41258d5..79714e9 100644 --- a/Taskfile.yaml +++ b/Taskfile.yaml @@ -33,8 +33,8 @@ tasks: security: - poetry run whispers {{.BUILD_DIR}} # Check for security issues - poetry run bandit --silent -r {{.BUILD_DIR}} - - pipx install tartufo - - tartufo scan-local-repo . + - python3.10 -m pip install tartufo # Only works on 3.10 + - python3.10 -m tartufo scan-local-repo . pytest: silent: false interactive: false diff --git a/pyproject.toml b/pyproject.toml index b07adb4..011b856 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -79,6 +79,7 @@ exclude-entropy-patterns = [ {path-pattern = 'Pipfile\.lock', pattern = '.'}, {path-pattern = 'README\.md', pattern = '.'}, {path-pattern = 'mapping\.cfg', pattern = '.'}, # Git secret + {path-pattern = 'techstack\.*', pattern = '.'}, ] [tool.poetry.group.test.dependencies]