From 5a0b2ab41220c52b2c794859dd62ef4af763a072 Mon Sep 17 00:00:00 2001 From: Andriy Oblivantsev Date: Sat, 29 Aug 2026 16:14:00 +0100 Subject: [PATCH] =?UTF-8?q?fix(ci):=20gitleaks=20=D1=87=D0=B5=D1=80=D0=B5?= =?UTF-8?q?=D0=B7=20=D0=B1=D0=B8=D0=BD=D0=B0=D1=80=D0=BD=D0=B8=D0=BA=20?= =?UTF-8?q?=D0=BD=D0=B0=20$GITHUB=5FWORKSPACE=20(Gitea=20runner)=20(#10)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/test.yml | 21 ++++++++++++++++----- 1 file changed, 16 insertions(+), 5 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 65c5850..22e7b66 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -35,14 +35,25 @@ jobs: echo "RANGE=$RANGE" >> "$GITHUB_ENV" echo "Scanning range: $RANGE" - # docker:// actions mount the workspace at /github/workspace — not the - # host path from ${{ github.workspace }} (that path does not exist in-container). + # Install the gitleaks binary instead of a docker action: the + # docker://zricethezav/gitleaks action hardcodes /github/workspace, + # which does not exist on the Gitea (act) runner. $GITHUB_WORKSPACE is + # the checkout dir on BOTH runners (GitHub and Gitea act). Mirrors the + # fix applied to 2dph (issue #142). - name: Gitleaks (diff-only, fail on leak) - uses: docker://zricethezav/gitleaks:latest env: GITLEAKS_RANGE: ${{ env.RANGE }} - with: - args: detect --source /github/workspace --log-opts="$GITLEAKS_RANGE" --redact --verbose + run: | + set -euo pipefail + curl -fsSLo /tmp/gitleaks.tar.gz \ + https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_x64.tar.gz + tar -xzf /tmp/gitleaks.tar.gz -C /tmp gitleaks + chmod +x /tmp/gitleaks + /tmp/gitleaks detect \ + --source "$GITHUB_WORKSPACE" \ + --log-opts="$GITLEAKS_RANGE" \ + --redact \ + --verbose test: name: Test (Go ${{ matrix.go }})