From 242c2cbec2b62b97dc57a75d41884de5f77a1c8b Mon Sep 17 00:00:00 2001 From: Joe Petrucelli Date: Sun, 9 Aug 2026 19:25:42 -0400 Subject: [PATCH 1/2] ci: call the org leak-scan workflow Verified clean against this rule set before wiring: a fresh clone of this repo scanned with no findings in the worktree or in history. No per-repo configuration: the scanner derives this repo's name from github.repository, so nothing here can go stale. --- .github/workflows/leak-scan.yml | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 .github/workflows/leak-scan.yml diff --git a/.github/workflows/leak-scan.yml b/.github/workflows/leak-scan.yml new file mode 100644 index 0000000..ed70278 --- /dev/null +++ b/.github/workflows/leak-scan.yml @@ -0,0 +1,17 @@ +# Checks that this repo publishes its own work and nothing else — no other +# project's name, no client's name, no path from an authoring machine. +# +# The scanner and its pattern set live once in Back-Road-Creative/.github. This +# file is the whole of the per-repo configuration, deliberately: the repo's own +# name is derived from ${{ github.repository }}, so there is nothing here to keep +# in sync and nothing to go stale. +name: leak-scan + +on: + pull_request: + push: + branches: [master] + +jobs: + leak-scan: + uses: Back-Road-Creative/.github/.github/workflows/leak-scan.yml@main From d28ce8020225a70b97f12b12ebd4f8e8f18762ce Mon Sep 17 00:00:00 2001 From: Joe Petrucelli Date: Sun, 9 Aug 2026 19:50:01 -0400 Subject: [PATCH 2/2] =?UTF-8?q?ci:=20retrigger=20leak-scan=20=E2=80=94=20t?= =?UTF-8?q?he=20reusable=20workflow=20now=20exists=20on=20main?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit