Parent: #41 (deferred from actionlint + concurrency harden)
Why
#41 skipped gitleaks so this public tip repo would take on fewer third-party Actions. Code now wants the optional public-safe scan.
In scope
- Add a fail-hard sibling job on
.github/workflows/validate.yml (or a dedicated workflow under .github/workflows/ if cleaner) that runs gitleaks.
- Prefer the same install pattern as Workflow lint: download a pinned official release binary + sha256 verify from the release checksums file. Prefer not adding a third-party GitHub Action if a binary install works.
- Scan the checkout on
pull_request and push to main (same triggers as validate). Timeout ≤ 10 minutes. No continue-on-error.
- Keep workflow
permissions: contents: read (or document any required bump). No new secrets beyond default GITHUB_TOKEN.
- Document pin (version + sha256 + source URL) in the PR body.
Out of scope
Acceptance
Capability
remote-ok
Parent: #41 (deferred from actionlint + concurrency harden)
Why
#41 skipped gitleaks so this public tip repo would take on fewer third-party Actions. Code now wants the optional public-safe scan.
In scope
.github/workflows/validate.yml(or a dedicated workflow under.github/workflows/if cleaner) that runs gitleaks.pull_requestandpushtomain(same triggers as validate). Timeout ≤ 10 minutes. Nocontinue-on-error.permissions: contents: read(or document any required bump). No new secrets beyond defaultGITHUB_TOKEN.Out of scope
Acceptance
.github/workflows/*(+ optional allowlist config under.github/if gitleaks needs one)Capability
remote-ok