Skip to content

feat(leak-scan): reusable workflow, allowlist contract, and docs - #5

Closed
joepetjr wants to merge 3 commits into
feat/leak-scan-scannerfrom
feat/leak-scan-reusable-workflow
Closed

joepetjr wants to merge 3 commits into
feat/leak-scan-scannerfrom
feat/leak-scan-reusable-workflow

Conversation

@joepetjr

@joepetjr joepetjr commented Aug 9, 2026

Copy link
Copy Markdown
Contributor

Summary

Stacked on #4 — merge that first.

Adds the reusable workflow callers point at, the allowlist contract, and the
documentation for both.

A caller adds one uses: line. There is no pattern list to copy, no vendored
script, and no setting that names the calling repo — the scanner derives that from
${{ github.repository }}.

A bug worth calling out: fetch-depth uses the quoted '0'/'1' form.
GitHub Actions treats the number 0 as falsy, so the natural
${{ inputs.history && 0 || 1 }} always evaluates to 1, and history mode would
have silently scanned a shallow clone and reported everything clean.

The allowlist

rule, path, match and reason are all required, and a reason under 20
characters is rejected. That is enforced by exiting non-zero on a malformed file,
not by convention — an unexplained exemption cannot be merged. An entry suppresses
a finding only where rule, path glob and matched substring all line up, so it
cannot quietly widen into a blanket. scope confines an entry to worktree,
history, or both.

There is a known failure mode this does not solve: an exemption whose reason has
been falsified by later code, with nothing rechecking it. The README says so and
asks for each entry to be re-derived when the file it covers is touched.

Test plan

python -m pytest scripts/test_leak_scan.py -q — 28 tests, up from 20. The eight
new ones cover the allowlist: a missing or too-short reason is fatal, a fully
explained entry is accepted, an entry cannot widen beyond its own rule/path/text,
and scope confines it to one side of the scan.

One 'uses:' line is all a caller needs — no pattern list, no copy of the script,
and no setting naming the calling repo.

The allowlist requires rule, path, match and a reason of at least 20 characters,
enforced by exiting non-zero on a malformed file rather than warning. An entry
suppresses a finding only where rule, path glob and matched text all line up, so
it cannot widen into a blanket exemption.

fetch-depth uses the quoted '0'/'1' form: Actions treats the number 0 as falsy,
so `inputs.history && 0 || 1` would always evaluate to 1 and history mode would
silently scan a shallow clone.
A caller cannot be green before the reusable workflow it calls exists on main,
and a workflow-not-found run is still a red run on the PR that has to merge
first. It ships with the other callers instead.
@joepetjr

joepetjr commented Aug 9, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #7: this PR auto-closed when the #4 merge deleted its base branch (feat/leak-scan-scanner) instead of retargeting. #7 carries the identical content rebuilt onto main, minus the accidentally committed scripts/pycache/*.pyc files, plus a .gitignore preventing their return.

joepetjr added a commit that referenced this pull request Aug 9, 2026
Rebuilt from PR #5, which was auto-closed when its base branch was deleted
by the #4 merge instead of retargeting. Same content, two fixes: the
committed scripts/__pycache__/*.pyc files are dropped, and a .gitignore
now prevents them from coming back.
@joepetjr
joepetjr deleted the feat/leak-scan-reusable-workflow branch August 10, 2026 01:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant