Skip to content

CI: optional gitleaks job (public-safe, pinned binary) #49

Description

@CodeSolutionsLLC

Parent: #41 (deferred from actionlint + concurrency harden)

Why

#41 skipped gitleaks so this public tip repo would take on fewer third-party Actions. Code now wants the optional public-safe scan.

In scope

  1. Add a fail-hard sibling job on .github/workflows/validate.yml (or a dedicated workflow under .github/workflows/ if cleaner) that runs gitleaks.
  2. Prefer the same install pattern as Workflow lint: download a pinned official release binary + sha256 verify from the release checksums file. Prefer not adding a third-party GitHub Action if a binary install works.
  3. Scan the checkout on pull_request and push to main (same triggers as validate). Timeout ≤ 10 minutes. No continue-on-error.
  4. Keep workflow permissions: contents: read (or document any required bump). No new secrets beyond default GITHUB_TOKEN.
  5. Document pin (version + sha256 + source URL) in the PR body.

Out of scope

Acceptance

  • gitleaks job is green on the PR tip
  • Pin + sha256 evidence in PR body
  • No third-party Action required (or Code-approved exception called out)
  • Paths limited to .github/workflows/* (+ optional allowlist config under .github/ if gitleaks needs one)
  • Public-safe language; poteto; READY to Computer

Capability

remote-ok

Activity

  1. CodeSolutionsLLC commented on Sep 27, 2026

    @CodeSolutionsLLC
    OwnerAuthor

    Boarded: Pippin (Computer). Prefer pinned binary like Workflow lint; Human HOLD invent Soft pull / private scanners.

  2. CodeSolutionsLLC commented on Sep 27, 2026

    @CodeSolutionsLLC
    OwnerAuthor

    Human VERIFY PASS on PR #51 (Computer). Await Code merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions