docs(volumes): record orphaned-volume archive + removal (legacy-bos-p… #142
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Secret Scan | |
| # ADR-0012 — gitleaks gate. Fails the PR/push if any new secret is detected. | |
| # Pre-commit hook is the first gate (per-clone, opt-in); this workflow is the | |
| # authoritative gate for everything that lands on a branch. | |
| # | |
| # Security note: this workflow takes NO untrusted user-supplied inputs (no | |
| # issue/PR title/body, no commit message text in run: blocks). The only | |
| # variables interpolated into shell are GHA-managed safe ones (RUNNER_TEMP, | |
| # GITHUB_PATH, uname output). No injection surface. | |
| on: | |
| push: | |
| branches: ["**"] | |
| pull_request: | |
| branches: ["**"] | |
| workflow_dispatch: | |
| # Use BOS-HQ self-hosted runner per repo convention. | |
| # (Same label as .github/workflows/self-hosted-smoke-test.yml.) | |
| jobs: | |
| gitleaks: | |
| name: gitleaks | |
| runs-on: [self-hosted, linux, x64, bos] | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| steps: | |
| - name: Checkout (full history) | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - name: Install gitleaks (pinned) | |
| env: | |
| GITLEAKS_VERSION: "8.21.2" | |
| run: | | |
| set -euo pipefail | |
| ARCH="$(uname -m)" | |
| case "$ARCH" in | |
| x86_64) GL_ARCH="x64" ;; | |
| aarch64|arm64) GL_ARCH="arm64" ;; | |
| *) echo "Unsupported arch: $ARCH" >&2; exit 1 ;; | |
| esac | |
| BIN_DIR="${RUNNER_TEMP}/gitleaks-bin" | |
| mkdir -p "$BIN_DIR" | |
| if [ ! -x "$BIN_DIR/gitleaks" ]; then | |
| curl -fsSL "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_${GL_ARCH}.tar.gz" \ | |
| | tar -xz -C "$BIN_DIR" gitleaks | |
| chmod +x "$BIN_DIR/gitleaks" | |
| fi | |
| echo "$BIN_DIR" >> "$GITHUB_PATH" | |
| "$BIN_DIR/gitleaks" version | |
| - name: Scan working tree (no-git mode) | |
| # `--no-git` scans the file contents on disk — catches secrets present | |
| # in the current commit even if `.gitleaks.toml` allowlists historical | |
| # commits. This is the gate that fails new leaks. | |
| run: | | |
| set -euo pipefail | |
| gitleaks detect \ | |
| --source . \ | |
| --config .gitleaks.toml \ | |
| --no-git \ | |
| --redact \ | |
| --verbose \ | |
| --exit-code 1 |