diff --git a/.github/leak-scan-allowlist.json b/.github/leak-scan-allowlist.json new file mode 100644 index 0000000..125305a --- /dev/null +++ b/.github/leak-scan-allowlist.json @@ -0,0 +1,28 @@ +{ + "allow": [ + { + "rule": "machine-path", + "path": "README.md", + "match": "/home/joe", + "reason": "The rule table documents the two account paths this rule catches; a doc that cannot name them documents nothing." + }, + { + "rule": "private-project", + "path": "README.md", + "match": "driftless", + "reason": "Explains why the lookahead ends the repo name instead of using a word boundary; the explanation needs the sibling name it once missed." + }, + { + "rule": "workspace-convention", + "path": "README.md", + "match": "_active/", + "reason": "The rule table names the monorepo conventions this rule catches; same self-documentation exemption as machine-path." + }, + { + "rule": "workspace-convention", + "path": "README.md", + "match": ".data/plans", + "reason": "The allowlist example must show a realistic match string, and a fake one would teach the wrong format." + } + ] +} diff --git a/.github/workflows/leak-scan-self.yml b/.github/workflows/leak-scan-self.yml new file mode 100644 index 0000000..494ffc0 --- /dev/null +++ b/.github/workflows/leak-scan-self.yml @@ -0,0 +1,11 @@ +# This repo is public too, so it holds itself to the rule it enforces elsewhere. +# The filename differs from leak-scan.yml because that name is taken here by the +# reusable workflow this one calls. +name: leak-scan +on: + pull_request: + push: + branches: [main] +jobs: + leak-scan: + uses: Back-Road-Creative/.github/.github/workflows/leak-scan.yml@main