Repository navigation
feat(reporting): lower view-backed object.report to SQL views and read it in every port (FR-044 Plan 2) #263
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: hygiene | |
| # Public-repo leak gate: scans a PR's added lines for absolute local paths and | |
| # private/other-project names (structural patterns; the private denylist is local-only). | |
| # The scanner lives in .githooks/leak-scan.sh so its pattern literals don't self-trip. | |
| # | |
| # THIN WRAPPER: scripts/ci-local.sh is the single definition of this check. This | |
| # workflow only checks out and calls it with `--only leak-scan`, pointing the scan at | |
| # the PR's base branch through MO_CI_LEAK_BASE. `leak-scan` is the status main's branch | |
| # protection requires, so the job name must not change. | |
| on: | |
| pull_request: | |
| permissions: | |
| contents: read | |
| jobs: | |
| leak-scan: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - name: Leak scan (added lines vs base) | |
| env: | |
| MO_CI_LEAK_BASE: origin/${{ github.base_ref }} | |
| run: scripts/ci-local.sh --only leak-scan --strict-toolchains |