GitNexus/.github/workflows
Gergő Magyar 938111ad45
fix(ci): stabilize gitleaks after #2024 (#2027)
* fix(ci): stabilize gitleaks after #2024 and clear history false positive

Fetch PR base/head SHAs before gitleaks-action so fork PRs do not fail with
ambiguous revision ranges. Add .gitleaks.toml allowlist for fake keys in
http-embedder tests, rename the redaction probe key, and point the README CI
badge at abhigyanpatwari/GitNexus.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): restore gitleaks default rules and narrow allowlist

Add [extend] useDefault = true so default secret rules run again. Replace
file-level allowlist with regexes for known fake embedding API keys.
Route PR SHAs through env vars in the gitleaks fetch step.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Update README.md

* Update README.md

* Update README.md

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 12:28:59 +01:00
..
ci-devcontainer.yml ci(devcontainer): harden smoke build against Docker Hub flakes (#1969) 2026-06-02 05:48:21 +01:00
ci-e2e.yml fix(security): Harden CI permissions (#1454) 2026-05-09 17:58:22 +01:00
ci-quality.yml fix(security): Harden CI permissions (#1454) 2026-05-09 17:58:22 +01:00
ci-report.yml ci: add fork-safe PR autofix pipeline (#1446) 2026-05-09 13:35:04 +01:00
ci-tests.yml fix(audit): Centralize heritage supertype matching (#1921/#1922) (#1940) 2026-06-01 13:16:17 +01:00
ci.yml refactor(ingestion): delete legacy call-resolution DAG + heritage processor (RING4-1, #942) (#2023) 2026-06-04 11:07:37 +01:00
claude.yml ci(claude): allow Bash in code-review job without interactive approval 2026-05-12 09:07:47 +01:00
codeql.yml chore(deps): bump github/codeql-action from 4.35.5 to 4.36.0 (#2017) 2026-06-04 07:02:20 +01:00
dependency-review.yml chore(deps): bump actions/dependency-review-action from 4.9.0 to 5.0.0 (#1739) 2026-05-21 12:07:22 +01:00
docker.yml chore(deps): bump docker/login-action from 4.1.0 to 4.2.0 (#2020) 2026-06-04 07:03:07 +01:00
gitleaks.yml fix(ci): stabilize gitleaks after #2024 (#2027) 2026-06-04 12:28:59 +01:00
pr-autofix-apply.yml chore(deps): bump actions/checkout from 5.0.0 to 6.0.2 (#1459) 2026-05-09 19:26:53 +01:00
pr-autofix-publish.yml feat(autofix): replace inline reviewdog with /autofix ChatOps button (#1458) 2026-05-09 16:32:38 +01:00
pr-autofix.yml fix(security): Pin Docker Node base images, remove runtime package-manager CVE surface, verify Trivy on PRs, and harden Dependabot policy (#1455) 2026-05-09 16:55:31 +01:00
pr-description-check.yml chore(deps): bump actions/github-script from 7.0.1 to 9.0.0 2026-04-15 20:17:08 +00:00
pr-labeler.yml chore(deps): bump release-drafter/release-drafter from 7.2.1 to 7.3.0 (#1740) 2026-05-21 12:07:07 +01:00
publish.yml refactor(ingestion): delete legacy call-resolution DAG + heritage processor (RING4-1, #942) (#2023) 2026-06-04 11:07:37 +01:00
scorecard.yml chore(deps): bump github/codeql-action from 4.35.5 to 4.36.0 (#2017) 2026-06-04 07:02:20 +01:00
tree-sitter-upgrade-readiness.yml chore(deps): tree-sitter 0.25 upgrade readiness monitor with daily Dependabot (#847) 2026-04-16 09:17:21 +01:00
triage-sweep.yml chore(deps): bump actions/cache from 5.0.4 to 5.0.5 (#840) 2026-04-15 13:36:38 +01:00
trivy.yml chore(deps): bump docker/build-push-action from 7.1.0 to 7.2.0 (#2010) 2026-06-04 07:02:44 +01:00
workflow-lint.yml chore(deps): bump github/codeql-action from 4.35.5 to 4.36.0 (#2017) 2026-06-04 07:02:20 +01:00