Skip to content

fix(ci): pin gitleaks-action to v2.3.9 (remove license requirement) - #643

Merged
d-oit merged 2 commits into
mainfrom
fix/pin-gitleaks-v2
Aug 11, 2026
Merged

fix(ci): pin gitleaks-action to v2.3.9 (remove license requirement)#643
d-oit merged 2 commits into
mainfrom
fix/pin-gitleaks-v2

Conversation

@d-oit

@d-oit d-oit commented Aug 11, 2026

Copy link
Copy Markdown
Owner

Fixes the pre-existing gitleaks failure documented in Plan 115.

Problem: gitleaks-action v3.0.0 requires a paid GITLEAKS_LICENSE secret, which is not configured. The step fails on every PR with `missing gitleaks license`.

Fix: Pin to gitleaks-action v2.3.9 (commit ff98106) which runs without a license. TruffleHog fallback remains for coverage.

Per maintainer decision (Plan 115).

@vercel

vercel Bot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
do-knowledge-studio Ready Ready Preview, v0 Aug 11, 2026 6:55pm

@deepsource-io

deepsource-io Bot commented Aug 11, 2026

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 0fae346...24bcb3a on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
JavaScript Aug 11, 2026 6:54p.m. Review ↗
Python Aug 11, 2026 6:54p.m. Review ↗
Shell Aug 11, 2026 6:54p.m. Review ↗
SQL Aug 11, 2026 6:54p.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@owl-watch owl-watch Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🦉 OwlWatch scanned this change — no actionable findings.

@codacy-production

Copy link
Copy Markdown
Contributor

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@owl-watch owl-watch Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🦉 OwlWatch scanned this change — no actionable findings.

@d-oit
d-oit merged commit c01ab3a into main Aug 11, 2026
29 checks passed
@d-oit
d-oit deleted the fix/pin-gitleaks-v2 branch August 11, 2026 19:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant