diff --git a/.github/workflows/push.yml b/.github/workflows/push.yml new file mode 100644 index 0000000..9b9f022 --- /dev/null +++ b/.github/workflows/push.yml @@ -0,0 +1,51 @@ +name: CI (lib) + +# First-ever CI for go/lib (ADR-KV-014). lib is publicly mirrored on +# code.tnxs.net, so every push and PR gets a build/vet/test job plus a +# gitleaks secret-scan job. lib is a Go library — no Dockerfile, no deploy. +on: + push: + branches: ['**'] + pull_request: + +defaults: + run: + shell: bash + +# Serialize per ref. PR runs cancel superseded validations; branch pushes never cancel. +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + +jobs: + test: + runs-on: [self-hosted, Linux] + permissions: { contents: read } + steps: + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 + + - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0 + with: + go-version: stable + + - name: go build ./... + run: go build ./... + + - name: go vet ./... + run: go vet ./... + + - name: go test ./... + run: go test ./... + + gitleaks: + runs-on: [self-hosted, Linux] + permissions: { contents: read } + steps: + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 + with: + fetch-depth: 0 + + - name: gitleaks detect (git history) + run: | + docker run --rm -v "$PWD:/repo" -w /repo zricethezav/gitleaks:latest \ + detect --source /repo --redact -v diff --git a/.gitleaks.toml b/.gitleaks.toml new file mode 100644 index 0000000..18c3893 --- /dev/null +++ b/.gitleaks.toml @@ -0,0 +1,20 @@ +title = "gitleaks config for code.tnxs.net/vernonkeenan/lib" + +[extend] +useDefault = true + +# ADR-KV-014: first-ever CI gitleaks scan surfaced 6 findings, all in +# swagger-codegen-generated Kazoo API client models and the vendored +# Kazoo swagger spec. Each is an illustrative `// Example:` / `example:` +# JWT hardcoded by the generator to document the shape of an auth_token +# field — a placeholder from the vendor's public API docs, not a +# credential issued to or used by this project. Scoped narrowly to the +# four generated files that triggered, not repo-wide. +[allowlist] +description = "Generated Kazoo API client/swagger example JWTs (not real secrets)" +paths = [ + '''api/kazoo/kazoo_models/get_account_descendent_response\.go''', + '''api/kazoo/kazoo_models/get_account_callflow_response\.go''', + '''api/kazoo/kazoo_models/get_account_response\.go''', + '''swagger/kazoo-telnexus\.yaml''', +]