feat(leak-scan): scanner that keeps one repo's content out of another - #4
Merged
Merged
Conversation
Checks that a public repo publishes its own work and nothing else: no sibling project's name, no client's name, no private-monorepo layout, no absolute path from an authoring machine. The repo's own name is derived from --self-name (fed by github.repository), so no repo can be left holding a stale "this is me" setting. A public sibling is not a finding, and the public set is read from the org API at scan time rather than hand-listed, because a hand-kept list goes stale the day a repo ships. Pattern set was validated against all thirteen public repos before landing. Candidates that fired on legitimate content were dropped, not tightened: GMS (a test fixture name in driftless, and "grant-management-software" in grantbridge), gomoveshift (a public brand), workspaces (ordinary English), openclaw (a third-party product these tools support), and a bare /home/<user>/ (documentation examples). The negative cases are pinned in the tests.
This was referenced Aug 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A leak scanner for the org's public repos, plus its tests and a self-test workflow.
It checks that a repository publishes its own work and nothing else: no sibling
project's name, no client's name, no layout convention from the private monorepo
several of these repos were extracted from, and no absolute path from an authoring
machine.
Two design points worth review:
--self-nameis fed from${{ github.repository }}, so a repo naming itself can never be a finding and norepo can be left holding a stale "this is me" setting the scan then stops
enforcing. The lookahead ends the name (
(?!driftless(?:\.git)?(?![\w.-])))rather than using
\b, because a word boundary sits betweendriftlessand the-ofdriftless-archive— the private sibling was the one name an earlierversion of this rule could not see. That case is pinned in the tests.
discloses nothing, and the public set is read from the org API at scan time
rather than hand-listed, since a hand-kept list goes stale the day a repo is
published. If the lookup fails the scan stops rather than guess. The endpoint is
public, so no extra token scope is needed.
The gate covers the worktree.
--historyscans every blob reachable from every refand is meant for audits, not the PR gate: only a force-push removes a published
blob, so a history gate would be permanently red on content no PR can fix.
Pattern set, and what was rejected
Every pattern was run against fresh clones of all thirteen public repos before it
was kept. Candidates that fired on legitimate content were dropped rather than
tightened:
GMSgomoveshift_active/.workspacesopenclaw/home/<user>/(general)/home/user/project. Only the two real authoring accounts are matched.backroadcreative.data/was tightened to require a following path segment, so a bare.gitignoreline — which names no internal file — is not a finding.
Test plan
python -m pytest scripts/test_leak_scan.py -q— 20 tests, run by the newselftestworkflow on every PR and push. The negative cases are the load-bearingones: an over-eager scanner gets switched off, and a switched-off scanner protects
nothing.
Also run end-to-end against fresh clones of all thirteen public repos; results are
in the accompanying report.