diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml index e405e1d..bec6a63 100644 --- a/.github/workflows/secret-scan.yml +++ b/.github/workflows/secret-scan.yml @@ -34,8 +34,20 @@ jobs: echo "Scanning range: $RANGE" - name: Gitleaks (diff-only, fail on leak) - uses: docker://zricethezav/gitleaks:latest env: GITLEAKS_RANGE: ${{ env.RANGE }} - with: - args: detect --source "${{ github.workspace }}" --log-opts="$GITLEAKS_RANGE" --redact --verbose + run: | + set -euo pipefail + # install the gitleaks binary (linux-amd64) instead of a docker action: + # the docker://zricethezav/gitleaks action hardcodes /github/workspace, + # which does not exist on the Gitea (act) runner. $GITHUB_WORKSPACE is the + # checkout dir on BOTH runners (GitHub and Gitea act). + curl -fsSLo /tmp/gitleaks.tar.gz \ + https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_x64.tar.gz + tar -xzf /tmp/gitleaks.tar.gz -C /tmp gitleaks + chmod +x /tmp/gitleaks + /tmp/gitleaks detect \ + --source "$GITHUB_WORKSPACE" \ + --log-opts="$GITLEAKS_RANGE" \ + --redact \ + --verbose