From 2c0df0d55fb03555b60481695554d75dceffce48 Mon Sep 17 00:00:00 2001 From: Andriy Oblivantsev Date: Thu, 27 Aug 2026 16:56:40 +0100 Subject: [PATCH] fix(ci): point gitleaks at /github/workspace in docker action The docker:// runner mounts the checkout at /github/workspace; using ${{ github.workspace }} (host path) made gitleaks fail with ENOENT. Co-authored-by: Cursor --- .github/workflows/test.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index b5bff99..65c5850 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -35,12 +35,14 @@ jobs: echo "RANGE=$RANGE" >> "$GITHUB_ENV" echo "Scanning range: $RANGE" + # docker:// actions mount the workspace at /github/workspace — not the + # host path from ${{ github.workspace }} (that path does not exist in-container). - name: Gitleaks (diff-only, fail on leak) uses: docker://zricethezav/gitleaks:latest env: GITLEAKS_RANGE: ${{ env.RANGE }} with: - args: detect --source "${{ github.workspace }}" --log-opts="$GITLEAKS_RANGE" --redact --verbose + args: detect --source /github/workspace --log-opts="$GITLEAKS_RANGE" --redact --verbose test: name: Test (Go ${{ matrix.go }})