diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 65c5850..22e7b66 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -35,14 +35,25 @@ jobs: echo "RANGE=$RANGE" >> "$GITHUB_ENV" echo "Scanning range: $RANGE" - # docker:// actions mount the workspace at /github/workspace — not the - # host path from ${{ github.workspace }} (that path does not exist in-container). + # Install the gitleaks binary instead of a docker action: the + # docker://zricethezav/gitleaks action hardcodes /github/workspace, + # which does not exist on the Gitea (act) runner. $GITHUB_WORKSPACE is + # the checkout dir on BOTH runners (GitHub and Gitea act). Mirrors the + # fix applied to 2dph (issue #142). - name: Gitleaks (diff-only, fail on leak) - uses: docker://zricethezav/gitleaks:latest env: GITLEAKS_RANGE: ${{ env.RANGE }} - with: - args: detect --source /github/workspace --log-opts="$GITLEAKS_RANGE" --redact --verbose + run: | + set -euo pipefail + curl -fsSLo /tmp/gitleaks.tar.gz \ + https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_x64.tar.gz + tar -xzf /tmp/gitleaks.tar.gz -C /tmp gitleaks + chmod +x /tmp/gitleaks + /tmp/gitleaks detect \ + --source "$GITHUB_WORKSPACE" \ + --log-opts="$GITLEAKS_RANGE" \ + --redact \ + --verbose test: name: Test (Go ${{ matrix.go }})