Skip to content

feat(leak-scan): scanner that keeps one repo's content out of another - #4

Merged
joepetjr merged 1 commit into
mainfrom
feat/leak-scan-scanner
Aug 9, 2026
Merged

joepetjr merged 1 commit into
mainfrom
feat/leak-scan-scanner

Conversation

@joepetjr

@joepetjr joepetjr commented Aug 9, 2026

Copy link
Copy Markdown
Contributor

Summary

A leak scanner for the org's public repos, plus its tests and a self-test workflow.
It checks that a repository publishes its own work and nothing else: no sibling
project's name, no client's name, no layout convention from the private monorepo
several of these repos were extracted from, and no absolute path from an authoring
machine.

Two design points worth review:

  • The repo's own name is derived, never configured. --self-name is fed from
    ${{ github.repository }}, so a repo naming itself can never be a finding and no
    repo can be left holding a stale "this is me" setting the scan then stops
    enforcing. The lookahead ends the name ((?!driftless(?:\.git)?(?![\w.-])))
    rather than using \b, because a word boundary sits between driftless and the
    - of driftless-archive — the private sibling was the one name an earlier
    version of this rule could not see. That case is pinned in the tests.
  • A public sibling is not a finding. Naming a repo anyone can already open
    discloses nothing, and the public set is read from the org API at scan time
    rather than hand-listed, since a hand-kept list goes stale the day a repo is
    published. If the lookup fails the scan stops rather than guess. The endpoint is
    public, so no extra token scope is needed.

The gate covers the worktree. --history scans every blob reachable from every ref
and is meant for audits, not the PR gate: only a force-push removes a published
blob, so a history gate would be permanently red on content no PR can fix.

Pattern set, and what was rejected

Every pattern was run against fresh clones of all thirteen public repos before it
was kept. Candidates that fired on legitimate content were dropped rather than
tightened:

Rejected Why
GMS A test fixture project name in driftless (134 hits) and the industry term "grant-management-software (GMS)" in grantbridge (10 hits).
gomoveshift A public brand. The internal service references it appears in are already caught by _active/.
workspaces Ordinary English — "multi-project workspaces", "CI workspaces".
openclaw A third-party product (docs.openclaw.ai) that rigscore legitimately supports as an MCP client.
/home/<user>/ (general) These repos document themselves with illustrative paths like /home/user/project. Only the two real authoring accounts are matched.
backroadcreative The brand email and domain, not the private repo.

.data/ was tightened to require a following path segment, so a bare .gitignore
line — which names no internal file — is not a finding.

Test plan

python -m pytest scripts/test_leak_scan.py -q — 20 tests, run by the new
selftest workflow on every PR and push. The negative cases are the load-bearing
ones: an over-eager scanner gets switched off, and a switched-off scanner protects
nothing.

Also run end-to-end against fresh clones of all thirteen public repos; results are
in the accompanying report.

Checks that a public repo publishes its own work and nothing else: no sibling
project's name, no client's name, no private-monorepo layout, no absolute path
from an authoring machine.

The repo's own name is derived from --self-name (fed by github.repository), so
no repo can be left holding a stale "this is me" setting. A public sibling is
not a finding, and the public set is read from the org API at scan time rather
than hand-listed, because a hand-kept list goes stale the day a repo ships.

Pattern set was validated against all thirteen public repos before landing.
Candidates that fired on legitimate content were dropped, not tightened: GMS
(a test fixture name in driftless, and "grant-management-software" in
grantbridge), gomoveshift (a public brand), workspaces (ordinary English),
openclaw (a third-party product these tools support), and a bare /home/<user>/
(documentation examples). The negative cases are pinned in the tests.
@joepetjr
joepetjr merged commit 90487dc into main Aug 9, 2026
2 checks passed
@joepetjr
joepetjr deleted the feat/leak-scan-scanner branch August 9, 2026 23:32
joepetjr added a commit that referenced this pull request Aug 9, 2026
Rebuilt from PR #5, which was auto-closed when its base branch was deleted
by the #4 merge instead of retargeting. Same content, two fixes: the
committed scripts/__pycache__/*.pyc files are dropped, and a .gitignore
now prevents them from coming back.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant