Conversation
One 'uses:' line is all a caller needs — no pattern list, no copy of the script, and no setting naming the calling repo. The allowlist requires rule, path, match and a reason of at least 20 characters, enforced by exiting non-zero on a malformed file rather than warning. An entry suppresses a finding only where rule, path glob and matched text all line up, so it cannot widen into a blanket exemption. fetch-depth uses the quoted '0'/'1' form: Actions treats the number 0 as falsy, so `inputs.history && 0 || 1` would always evaluate to 1 and history mode would silently scan a shallow clone.
A caller cannot be green before the reusable workflow it calls exists on main, and a workflow-not-found run is still a red run on the PR that has to merge first. It ships with the other callers instead.
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Stacked on #4 — merge that first.
Adds the reusable workflow callers point at, the allowlist contract, and the
documentation for both.
A caller adds one
uses:line. There is no pattern list to copy, no vendoredscript, and no setting that names the calling repo — the scanner derives that from
${{ github.repository }}.A bug worth calling out:
fetch-depthuses the quoted'0'/'1'form.GitHub Actions treats the number
0as falsy, so the natural${{ inputs.history && 0 || 1 }}always evaluates to1, and history mode wouldhave silently scanned a shallow clone and reported everything clean.
The allowlist
rule,path,matchandreasonare all required, and areasonunder 20characters is rejected. That is enforced by exiting non-zero on a malformed file,
not by convention — an unexplained exemption cannot be merged. An entry suppresses
a finding only where rule, path glob and matched substring all line up, so it
cannot quietly widen into a blanket.
scopeconfines an entry toworktree,history, or both.There is a known failure mode this does not solve: an exemption whose reason has
been falsified by later code, with nothing rechecking it. The README says so and
asks for each entry to be re-derived when the file it covers is touched.
Test plan
python -m pytest scripts/test_leak_scan.py -q— 28 tests, up from 20. The eightnew ones cover the allowlist: a missing or too-short reason is fatal, a fully
explained entry is accepted, an entry cannot widen beyond its own rule/path/text,
and
scopeconfines it to one side of the scan.