Skip to content

feat: public Gitleaks reusable workflow - #2

Closed
adamkoy wants to merge 1 commit into
mainfrom
feat/public-secret-scan
Closed

adamkoy wants to merge 1 commit into
mainfrom
feat/public-secret-scan

Conversation

@adamkoy

@adamkoy adamkoy commented Sep 1, 2026

Copy link
Copy Markdown

Summary

  • GitHub will not let a public repo call a reusable workflow in private m0-pipelines. PYUSDx leftover Security already fails in 0s for that reason.
  • Moves the org Gitleaks composite, gitleaks.toml baseline, and workflow_call here (this repo is already public) so callers can use:
uses: m0-platform/.github/.github/workflows/secret-scan.yml@main
  • Same EVM rules as m0-pipelines (evm-32-byte-hex / bare-32-byte-hex). Repo .gitleaks.toml still extends the baseline via useDefault = true.
  • Follow-up: point m0-pipelines secret-scan at this repo so private and public share one copy.

Test plan

  • Merge this PR first (callers pin @main)
  • Confirm Test Gitleaks config fixtures are green
  • Then land caller PRs on protocol, common, evm-m-extensions, wrapped-m-token, solana-m, ttg, portals, PYUSDx, mUSD, documentation, subgraphs, m-core

Public GitHub repos cannot call private m0-pipelines reusable workflows.
Host the secret-scan composite and org baseline here so protocol and other
public repos can use the same EVM private-key rules.
@adamkoy adamkoy closed this Sep 1, 2026
@adamkoy
adamkoy deleted the feat/public-secret-scan branch September 1, 2026 20:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant