Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
# The org secret-scan ruleset and the reusable workflows are fetched or called
# by every repo in the org, so a change here takes effect fleet-wide.
/.gitleaks.toml @CameronBrooks11
/.github/workflows/ @CameronBrooks11
29 changes: 28 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,31 @@ Organization-level defaults for the FlowMatrix-AI GitHub org.
- `profile/README.md` — public org profile (shown on github.com/FlowMatrix-AI)
- `SECURITY.md` — vulnerability reporting guidance (applies to all repos without their own)
- `PULL_REQUEST_TEMPLATE.md` — default PR template (applies to all repos without their own)
- `ISSUE_TEMPLATE/` — default issue forms (applies to all repos without their own)
- `ISSUE_TEMPLATE/` — default issue forms (applies to all repos without their own)

## This repository must stay public

Making it private breaks three things, and the third is the least visible:

| Depends on this repo being public | What breaks if it goes private |
|---|---|
| The org profile (`profile/README.md`) | the profile goes dark; GitHub requires a public `.github` |
| The default community health files (`ISSUE_TEMPLATE/`, `PULL_REQUEST_TEMPLATE.md`, `SECURITY.md`) | they stop applying org-wide ("a repository for default files cannot be private") |
| The unauthenticated fetch of `.gitleaks.toml` in `.github/workflows/gitleaks.yml` | the required `gitleaks / gitleaks` check fails in every calling repo: `raw.githubusercontent.com` returns 404 for a private repo |

## `.gitleaks.toml` is live everywhere the moment it merges

Callers pin `gitleaks.yml` by digest, but that pins the workflow code, not the
ruleset it runs with: the workflow fetches `.gitleaks.toml` from `main` on every
run. A change to it (an over-broad allowlist in particular) changes what every
repo detects on its next scan, and fails open: checks stay green. `CODEOWNERS`
names an owner for it and for the workflows.

The fetch is deliberately fail-closed (`curl -f`, no fallback), so a scan never
runs with an empty or different ruleset. The accepted cost: if
`raw.githubusercontent.com` is unreachable, the required check fails and no repo
in the org can merge until it is back.

A repo that needs its own `.gitleaks.toml` must `[extend] path =
".gitleaks.org.toml"`: a local config otherwise replaces the org ruleset
entirely, and the scan still shows green.
Loading