eric] Google OAuth via cloud-proxy + gitleaks CI

This commit is contained in:
ciregenz
2026-05-06 13:28:35 -07:00
parent d8a1e333be
commit 11487456b5
6 changed files with 144 additions and 197 deletions
+35
View File
@@ -0,0 +1,35 @@
name: gitleaks
# Block PRs that introduce hardcoded credentials. Runs the upstream gitleaks
# action against the diff (PR) or full history (push to main). False
# positives in the working tree are caught by the gitleaks-action's own
# allowlist mechanism — extend .gitleaks.toml at repo root rather than
# editing this workflow.
on:
pull_request:
branches: ['**']
push:
branches: [main, 'eric/**', 'haik/**', 'arnav/**']
permissions:
contents: read
pull-requests: read
jobs:
scan:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
# Full history needed so gitleaks can scan all new commits in a PR.
fetch-depth: 0
- name: Run gitleaks
uses: gitleaks/gitleaks-action@v2
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# Treat any high-confidence finding as a hard fail.
GITLEAKS_ENABLE_UPLOAD_ARTIFACT: 'true'
GITLEAKS_ENABLE_SUMMARY: 'true'
+4
View File
@@ -19,6 +19,10 @@ name: Release (Windows)
# AZURE_SIGNING_CERT_PROFILE Mist-Windows-Signing
# GOOGLE_OAUTH_CLIENT_ID shipped in production .env (Google OAuth)
# GOOGLE_OAUTH_CLIENT_SECRET shipped in production .env (Google OAuth)
# v1.0.29 cloud-proxied the OAuth flow itself,
# but the bundled google_workspace_mcp still
# requires CLIENT_SECRET at startup. v1.0.30
# plans to remove this dependency.
on:
push: