fix(ci): point gitleaks at /github/workspace in docker action
The docker:// runner mounts the checkout at /github/workspace; using
${{ github.workspace }} (host path) made gitleaks fail with ENOENT.
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -35,12 +35,14 @@ jobs:
|
|||||||
echo "RANGE=$RANGE" >> "$GITHUB_ENV"
|
echo "RANGE=$RANGE" >> "$GITHUB_ENV"
|
||||||
echo "Scanning range: $RANGE"
|
echo "Scanning range: $RANGE"
|
||||||
|
|
||||||
|
# docker:// actions mount the workspace at /github/workspace — not the
|
||||||
|
# host path from ${{ github.workspace }} (that path does not exist in-container).
|
||||||
- name: Gitleaks (diff-only, fail on leak)
|
- name: Gitleaks (diff-only, fail on leak)
|
||||||
uses: docker://zricethezav/gitleaks:latest
|
uses: docker://zricethezav/gitleaks:latest
|
||||||
env:
|
env:
|
||||||
GITLEAKS_RANGE: ${{ env.RANGE }}
|
GITLEAKS_RANGE: ${{ env.RANGE }}
|
||||||
with:
|
with:
|
||||||
args: detect --source "${{ github.workspace }}" --log-opts="$GITLEAKS_RANGE" --redact --verbose
|
args: detect --source /github/workspace --log-opts="$GITLEAKS_RANGE" --redact --verbose
|
||||||
|
|
||||||
test:
|
test:
|
||||||
name: Test (Go ${{ matrix.go }})
|
name: Test (Go ${{ matrix.go }})
|
||||||
|
|||||||
Reference in New Issue
Block a user