From 21096c6fd70161a579350e5cc0973cdce13bc238 Mon Sep 17 00:00:00 2001 From: Andriy Oblivantsev Date: Thu, 3 Sep 2026 05:20:23 +0100 Subject: [PATCH 1/2] funding: eSlider support links (sponsors, ko-fi, liberapay, patreon, polar) --- .github/FUNDING.yml | 6 ++++++ 1 file changed, 6 insertions(+) create mode 100644 .github/FUNDING.yml diff --git a/.github/FUNDING.yml b/.github/FUNDING.yml new file mode 100644 index 0000000..91e8017 --- /dev/null +++ b/.github/FUNDING.yml @@ -0,0 +1,6 @@ +github: eSlider +ko_fi: eslider +liberapay: eslider +patreon: eslider +custom: + - https://polar.sh/eslider -- 2.54.0 From 1607f760db917158a3f5bc6f96d0549bd8e3dab7 Mon Sep 17 00:00:00 2001 From: Andriy Oblivantsev Date: Sun, 6 Sep 2026 02:45:29 +0100 Subject: [PATCH 2/2] ci(secret-scan): fix gitleaks --source path (docker action host path) (#3) The docker://zricethezav/gitleaks action mounts the workspace at /github/workspace, but --source pointed at the host path from github.workspace ($HOME/runner/work/...), which does not exist inside the container -> 'stat ...: no such file or directory' on every run. Follow the 2dph canon (ci.yml secret-scan): install the gitleaks binary instead of the docker action and scan GITHUB_WORKSPACE - works on both GitHub and Gitea act runners. --- .github/workflows/secret-scan.yml | 18 +++++++++++++++--- 1 file changed, 15 insertions(+), 3 deletions(-) diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml index e405e1d..bec6a63 100644 --- a/.github/workflows/secret-scan.yml +++ b/.github/workflows/secret-scan.yml @@ -34,8 +34,20 @@ jobs: echo "Scanning range: $RANGE" - name: Gitleaks (diff-only, fail on leak) - uses: docker://zricethezav/gitleaks:latest env: GITLEAKS_RANGE: ${{ env.RANGE }} - with: - args: detect --source "${{ github.workspace }}" --log-opts="$GITLEAKS_RANGE" --redact --verbose + run: | + set -euo pipefail + # install the gitleaks binary (linux-amd64) instead of a docker action: + # the docker://zricethezav/gitleaks action hardcodes /github/workspace, + # which does not exist on the Gitea (act) runner. $GITHUB_WORKSPACE is the + # checkout dir on BOTH runners (GitHub and Gitea act). + curl -fsSLo /tmp/gitleaks.tar.gz \ + https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_x64.tar.gz + tar -xzf /tmp/gitleaks.tar.gz -C /tmp gitleaks + chmod +x /tmp/gitleaks + /tmp/gitleaks detect \ + --source "$GITHUB_WORKSPACE" \ + --log-opts="$GITLEAKS_RANGE" \ + --redact \ + --verbose -- 2.54.0