mirror of https://github.com/vernonkeenan/lib
lib is publicly mirrored on code.tnxs.net and had no CI at all. Add .github/workflows/push.yml gating every push/PR on the private self-hosted runner (ADR-KV-004): a test job (go build/vet/test) and a gitleaks secret-scan job using the official docker image directly (gitleaks/gitleaks-action needs an org license we don't have). The gitleaks history scan surfaced 6 findings, all illustrative `example:` JWTs hardcoded by swagger-codegen into the generated Kazoo API client models and the vendored Kazoo swagger spec — placeholders from the vendor's public docs, not real credentials. Added a minimal .gitleaks.toml allowlist scoped to just those four generated files so CI runs clean without masking real findings elsewhere. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| workflows | ||