From cc988c4610cf29be9b4bf54de14cac30926809e3 Mon Sep 17 00:00:00 2001 From: quadseven <59060157+quadseven@users.noreply.github.com> Date: Thu, 24 Sep 2026 00:18:24 -0400 Subject: [PATCH] ci(leak-scan): turn on the shared deny-list layer Pass the shared SSM deny-list parameter and the LEAK_SCAN_ROLE_ARN secret to the reusable, grant id-token: write for the OIDC read, and bump the reusable pin to infra-public main (includes infra-public#106, which reads the list one term per line and redacts hits). Mode unchanged. Part of #83 Claude-Session: https://claude.ai/code/session_01Ht7JaVzv2aacJ9r6Srso9r --- .github/workflows/check.leak-scan.yml | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/.github/workflows/check.leak-scan.yml b/.github/workflows/check.leak-scan.yml index a61bffe..eee17f6 100644 --- a/.github/workflows/check.leak-scan.yml +++ b/.github/workflows/check.leak-scan.yml @@ -17,14 +17,27 @@ name: check.leak-scan # allowed-repo-refs: repos this one cites by `#123` as a matter of # course. This repo's own refs are always exempt and need no entry. +# DENY-LIST LAYER. Terms with no generic shape (people, products, projects) +# are read at run time from the SSM parameter below, through the role in the +# LEAK_SCAN_ROLE_ARN secret. That role can read this one parameter and +# nothing else, and trusts only pull_request runs of the public repos that +# share it. The terms never live in this repo, the log shows only how many +# were loaded, and a hit is redacted. A fork PR gets no secrets, so the scan fails closed there rather +# than running without the list. + on: pull_request: types: [opened, synchronize, reopened, edited] jobs: leak-scan: - uses: quadseven/infra-public/.github/workflows/_reusable.leak-scan.yml@c9bd945704f0d33f1fa576eb4a5d469910c483df + uses: quadseven/infra-public/.github/workflows/_reusable.leak-scan.yml@273755079c88172df39501ee6914fd878c0920bc permissions: contents: read + # Mint the OIDC token for the deny-list read role. + id-token: write with: allowed-repo-refs: infra, infra-public + deny-list-ssm-param: /infra/leak-scan/deny-list + secrets: + aws-role-arn: ${{ secrets.LEAK_SCAN_ROLE_ARN }}