Skip to content

docs(volumes): record orphaned-volume archive + removal (legacy-bos-p… #142

docs(volumes): record orphaned-volume archive + removal (legacy-bos-p…

docs(volumes): record orphaned-volume archive + removal (legacy-bos-p… #142

Workflow file for this run

name: Secret Scan
# ADR-0012 — gitleaks gate. Fails the PR/push if any new secret is detected.
# Pre-commit hook is the first gate (per-clone, opt-in); this workflow is the
# authoritative gate for everything that lands on a branch.
#
# Security note: this workflow takes NO untrusted user-supplied inputs (no
# issue/PR title/body, no commit message text in run: blocks). The only
# variables interpolated into shell are GHA-managed safe ones (RUNNER_TEMP,
# GITHUB_PATH, uname output). No injection surface.
on:
push:
branches: ["**"]
pull_request:
branches: ["**"]
workflow_dispatch:
# Use BOS-HQ self-hosted runner per repo convention.
# (Same label as .github/workflows/self-hosted-smoke-test.yml.)
jobs:
gitleaks:
name: gitleaks
runs-on: [self-hosted, linux, x64, bos]
permissions:
contents: read
pull-requests: read
steps:
- name: Checkout (full history)
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Install gitleaks (pinned)
env:
GITLEAKS_VERSION: "8.21.2"
run: |
set -euo pipefail
ARCH="$(uname -m)"
case "$ARCH" in
x86_64) GL_ARCH="x64" ;;
aarch64|arm64) GL_ARCH="arm64" ;;
*) echo "Unsupported arch: $ARCH" >&2; exit 1 ;;
esac
BIN_DIR="${RUNNER_TEMP}/gitleaks-bin"
mkdir -p "$BIN_DIR"
if [ ! -x "$BIN_DIR/gitleaks" ]; then
curl -fsSL "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_${GL_ARCH}.tar.gz" \
| tar -xz -C "$BIN_DIR" gitleaks
chmod +x "$BIN_DIR/gitleaks"
fi
echo "$BIN_DIR" >> "$GITHUB_PATH"
"$BIN_DIR/gitleaks" version
- name: Scan working tree (no-git mode)
# `--no-git` scans the file contents on disk — catches secrets present
# in the current commit even if `.gitleaks.toml` allowlists historical
# commits. This is the gate that fails new leaks.
run: |
set -euo pipefail
gitleaks detect \
--source . \
--config .gitleaks.toml \
--no-git \
--redact \
--verbose \
--exit-code 1