Skip to content

ci(secret-scan): fix gitleaks --source path (docker action host path) - #14

Merged
eSlider merged 1 commit into
mainfrom
fix/secret-scan-workflow#3
Sep 6, 2026
Merged

eSlider merged 1 commit into
mainfrom
fix/secret-scan-workflow#3

Conversation

@eSlider

@eSlider eSlider commented Sep 6, 2026

Copy link
Copy Markdown
Owner

Fixes #3 (GitHub Actions Secret scan red on main).

Root cause: the docker://zricethezav/gitleaks action mounts the workspace at /github/workspace, but --source "${{ github.workspace }}" expanded to the host path (/home/runner/work/go-config/go-config) which does not exist inside the container -> stat ...: no such file or directory on every run (run 33714677787).

Fix follows the 2dph canon: install the pinned gitleaks v8.30.1 binary instead of the docker action and scan $GITHUB_WORKSPACE (same dir on GitHub and Gitea act runners). Range logic unchanged.

…#3)

The docker://zricethezav/gitleaks action mounts the workspace at
/github/workspace, but --source pointed at the host path from
github.workspace ($HOME/runner/work/...), which does not exist inside the
container -> 'stat ...: no such file or directory' on every run.

Follow the 2dph canon (ci.yml secret-scan): install the gitleaks binary
instead of the docker action and scan GITHUB_WORKSPACE - works on both
GitHub and Gitea act runners.
@eSlider
eSlider merged commit eb90564 into main Sep 6, 2026
8 checks passed
@eSlider
eSlider deleted the fix/secret-scan-workflow#3 branch September 6, 2026 01:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant