Skip to content

修正密鑰外洩掃描/修正密钥泄露扫描/Fix the secret scan/シークレットスキャンの修正 - #13

Merged
hitoshic1982 merged 2 commits into
mainfrom
ci/gitleaks-oss-cli
Oct 8, 2026
Merged

hitoshic1982 merged 2 commits into
mainfrom
ci/gitleaks-oss-cli

Conversation

@hitoshic1982

@hitoshic1982 hitoshic1982 commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

繁體中文

修正每週密鑰外洩掃描一直失敗的問題。

  • 原因:gitleaks/gitleaks-action 對組織擁有的倉庫要求付費授權碼;專案移入 flameblade-studio 組織後,掃描每次都以「缺少授權碼」中止,實際上沒有執行任何掃描。
  • 修正:改用 Gitleaks 開源版 CLI v8.30.1(固定版本並核對 SHA-256),與墨寒專案相同做法,不需要授權碼。
  • 稽核程式改為檢查固定版本的開源 CLI 與 SHA-256 核對,不再要求舊的 action。
  • Linux 封裝原本下載 appimagetool 的 continuous 版,上游原地替換後指紋失效;改為固定 1.9.1 版與其 SHA-256(本機已下載核對)。
  • 不影響任何程式或使用者功能;本機稽核程式全數通過。

简体中文

修正每周密钥泄露扫描持续失败的问题。

  • 原因:gitleaks/gitleaks-action 对组织拥有的仓库要求付费许可证;项目迁入 flameblade-studio 组织后,扫描每次都因“缺少许可证”中止,实际上没有执行任何扫描。
  • 修正:改用 Gitleaks 开源版 CLI v8.30.1(固定版本并核对 SHA-256),与墨寒项目做法相同,无需许可证。
  • 审计程序改为检查固定版本的开源 CLI 与 SHA-256 核对,不再要求旧的 action。
  • Linux 打包原本下载 appimagetool 的 continuous 版,上游原地替换后指纹失效;改为固定 1.9.1 版与其 SHA-256(本机已下载核对)。
  • 不影响任何程序或用户功能;本机审计程序全部通过。

English

Fix the weekly secret scan that has been failing.

  • Cause: gitleaks/gitleaks-action requires a paid license key for organization-owned repositories; since the move into the flameblade-studio organization every run stopped with "missing gitleaks license" and no scan actually ran.
  • Fix: use the open-source Gitleaks CLI v8.30.1 with a pinned SHA-256 check, the same approach as the MoHan project, which needs no license.
  • The audit harness now checks for the version-pinned CLI and its SHA-256 verification instead of the old action.
  • Linux packaging downloaded appimagetool's continuous asset, whose digest broke after an in-place upstream replacement; it now pins the tagged 1.9.1 release and its SHA-256 (verified by local download).
  • No application code or user-facing behavior changes; the audit harnesses pass locally.

日本語

毎週のシークレット漏えいスキャンが失敗し続けている問題を修正します。

  • 原因:gitleaks/gitleaks-action は組織所有のリポジトリに有償ライセンスキーを要求します。flameblade-studio 組織へ移行してから毎回「ライセンスキーなし」で停止し、実際にはスキャンが実行されていませんでした。
  • 修正:墨寒プロジェクトと同じく、Gitleaks オープンソース版 CLI v8.30.1(固定版、SHA-256 照合付き)を使い、ライセンスキーを不要にします。
  • 監査プログラムは旧 action の代わりに、固定版 CLI と SHA-256 照合を確認します。
  • Linux パッケージは appimagetool の continuous 版を取得しており、上流での差し替えでハッシュが合わなくなっていたため、タグ付き 1.9.1 版とその SHA-256 に固定しました(ローカルでダウンロードして照合済み)。
  • アプリのコードや利用者向けの動作は変わらず、監査プログラムはローカルですべて合格しています。

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9fb962563a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/secret-defense.yml
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T00:09:34.649974Z 9fb9625 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@hitoshic1982
hitoshic1982 merged commit e98625c into main Oct 8, 2026
16 checks passed
@hitoshic1982
hitoshic1982 deleted the ci/gitleaks-oss-cli branch October 8, 2026 00:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant