Repository navigation
ci(security): scan only the checked-out history in the Gitleaks job - #1633
Merged
Merged
Conversation
lusoris
force-pushed
the
ci/gitleaks-scan-checked-out-history
branch
from
September 29, 2026 16:47
189e0ea to
59e6308
Compare
gitleaks ran git log --all over a fetch-depth: 0 checkout, so a finding on any branch, even a force-pushed-away commit still in the fetch, failed every other pull request (#1628 on 2026-09-29). Pass --log-opts so each run scans HEAD's history: master plus the PR's commits on a pull request. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
lusoris
force-pushed
the
ci/gitleaks-scan-checked-out-history
branch
from
September 30, 2026 11:43
59e6308 to
b99bef0
Compare
This was referenced Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
On 2026-09-29, #1628 failed its Gitleaks check on
build-config.env:218of commita74842e16. #1628 does not contain that commit. The commit was a pre-rebase version offix/release-oneapi-image-runtime(#1629), and a force-push had already replaced it. The finding itself was ageneric-api-keyfalse positive on an apt signing-key fingerprint.The job checks out with
fetch-depth: 0, which fetches every branch, and runsgitleaks detectwithout--log-opts. In that case gitleaks runsgit log --full-history --all, so every pull request scanned every branch in the repository. One branch's finding therefore failed all the others, including findings in commits that had already been replaced.This PR passes
--log-opts="--full-history HEAD". On a pull request, HEAD is the merge commit, so the scan covers master's history plus the PR's own commits. On pushes to master and on the schedule, it covers master. A new self-test step pins the option.Type
build/ci— tooling / infraChecklist
make format && make lintis green locally. Not run in full: one workflow step and one Python test changed; actionlint and the test pass.python3 scripts/ci/run_meson_test.py -- -C build. Not applicable: no native code changed.Bug-status hygiene (ADR-0165)
T-CI-GITLEAKS-SCANS-ALL-BRANCHES-2026-09-29added to Recently closed.Netflix golden-data gate (ADR-0024)
assertAlmostEqual(...)score in the Netflix golden Python tests.Deep-dive deliverables (ADR-0108)
base..headinstead would skip master's history on pull requests, and droppingfetch-depth: 0would break the history scan.AGENTS.mdinvariant note — no rebase-sensitive invariants; the self-test enforces the option.changelog.d/fixed/gitleaks-scan-checked-out-history.md.no docs needed: CI-internal scan scope with no user-discoverable surface.
Reproducer
Negative control: with the
--log-optsline removed,test_scans_checked_out_history_onlyfails.Scope change: branches without an open pull request are no longer scanned by this job. GitHub secret scanning still covers every push.
🤖 Generated with Claude Code