Skip to content

fix: harden snapshot validation and spice handling #113

fix: harden snapshot validation and spice handling

fix: harden snapshot validation and spice handling #113

Workflow file for this run

name: gitleaks
on:
push:
pull_request:
permissions:
contents: read
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Install gitleaks CLI
run: |
GITLEAKS_VERSION=8.21.2
curl -sSfL \
"https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" \
| sudo tar -xz -C /usr/local/bin gitleaks
- name: Run gitleaks (workspace scan)
run: |
gitleaks detect --redact --source . \
--config .gitleaks.toml \
--report-format=sarif --report-path=results.sarif --exit-code=1
- name: Upload SARIF report
if: always()
uses: actions/upload-artifact@v4
with:
name: gitleaks-results
path: results.sarif