Skip to content

chore(ci): clear remaining node20 path before 2026-06-02 deadline - #163

Merged
Twodragon0 merged 1 commit into
mainfrom
chore/node20-cleanup-gitleaks-cli
May 21, 2026
Merged

Twodragon0 merged 1 commit into
mainfrom
chore/node20-cleanup-gitleaks-cli

Conversation

@Twodragon0

Copy link
Copy Markdown
Owner

Summary

Audit of every SHA-pinned action in .github/workflows/lint.yml (12 actions in total) found exactly one real node20 user remaining after #157 bumped actions/dependency-review-action to v5.0.0: gitleaks/gitleaks-action@ff98106e (v2.3.9, latest available).

The upstream node24 migration is in flight (gitleaks-action#215, still open as of 2026-05-19) so waiting for a tagged release risks missing the 2026-06-02 GitHub deprecation deadline (D-12).

This PR:

  1. Replaces gitleaks/gitleaks-action@v2.3.9 with a direct gitleaks CLI install (pinned to v8.30.1, sha256 verified against published checksums) + gitleaks dir scan against the working tree. Same security gate, no node20 dependency.
  2. Cleans up two stale workflow comments uncovered during the audit:

Audit table

Action Pinned SHA Runtime Status
actions/checkout de0fac2e (v6) node24 OK
actions/setup-python a309ff8b node24 OK
actions/upload-artifact 043fb46d (v7) node24 OK
actions/download-artifact 3e5f45b2 (v8) node24 OK
actions/dependency-review-action a1d282b3 (v5.0.0) node24 OK (bumped in #157)
codecov/codecov-action e79a6962 (v6.0.1) composite OK
dependabot/fetch-metadata 25dd0e34 (v3.1.0) node24 OK
lycheeverse/lychee-action 8646ba30 composite OK
mikepenz/action-junit-report 3a81627b (v6.4.1) node24 OK
treosh/lighthouse-ci-action 3e7e23fb (v12.6.2) node24 OK
DavidAnson/markdownlint-cli2-action ded1f948 (v23) node24 OK
docker/build-push-action bcafcacb node24 OK
docker/setup-buildx-action 4d04d5d9 node24 OK
ludeeus/action-shellcheck 00cae500 composite (was misdocumented as node20) OK — comment fixed
gitleaks/gitleaks-action ff98106e (v2.3.9) node20 Replaced with CLI

Why CLI replacement is safe

  • gitleaks CLI v8.30.1 has been the project's pre-commit hook engine for months — no behaviour delta.
  • gitleaks dir . (the v8.20+ replacement for legacy detect --no-git) scans the working tree, which is exactly what gitleaks-action was effectively doing for PR/push events.
  • The action's only unique feature (PR comment on leak) is already covered by GitGuardian Security Checks (separate required check) + the local pre-commit gitleaks hook that fires on every developer push.
  • Binary integrity: sha256 from the upstream checksums file at https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_checksums.txt.

Test plan

  • YAML parses (python3 -c "import yaml; yaml.safe_load(...)")
  • Local gitleaks dir . --config .gitleaks.toml --redact --no-banner --exit-code 1 against working tree → exit 0
  • CI gitleaks job green on this PR with the new CLI invocation
  • No regression in other lint.yml jobs
  • After merge: monitor 2026-06-02 deadline behaviour (no further action expected)

Follow-up

When gitleaks/gitleaks-action#215 is tagged on node24, we can optionally migrate back to get the PR-comment feature. Not urgent.

🤖 Generated with Claude Code

Copilot AI review requested due to automatic review settings May 21, 2026 03:27

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the CI lint workflow to remove the last remaining Node 20–based GitHub Action usage ahead of the 2026-06-02 deprecation by replacing gitleaks/gitleaks-action with a pinned, checksum-verified Gitleaks CLI install and scan. It also corrects stale/inaccurate workflow comments discovered during the audit.

Changes:

  • Replace gitleaks/gitleaks-action (node20) with direct Gitleaks CLI download (v8.30.1) + gitleaks dir scan.
  • Update workflow comments for actions/dependency-review-action (now node24) and clarify ludeeus/action-shellcheck is composite (no node runtime).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +365 to +367
GITLEAKS_VERSION: "8.30.1"
# https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_checksums.txt
GITLEAKS_SHA256: "551f6fc83ea457d62a0d98237cbad105af8d557003051f41f3e7ca7b3f2470eb"
Audit of every SHA-pinned action in .github/workflows/ found one
real node20 user left after #157 bumped dependency-review-action to
v5.0.0: gitleaks/gitleaks-action@ff98106e (v2.3.9, latest). The
upstream node24 migration is in flight (gitleaks/gitleaks-action#215,
still open as of 2026-05-19), so waiting for a tagged release would
risk missing the GitHub deadline.

Replace the action wrapper with a direct gitleaks CLI install plus
`gitleaks dir` scan against the working tree. CLI binary is pinned to
v8.30.1 with sha256 verification against the published checksums file.
This preserves the secret-scan layer while removing the node20
dependency. PR-comment functionality is already covered by the local
pre-commit gitleaks hook and the separate GitGuardian Security Checks
service.

Also cleans up two stale workflow comments uncovered during the audit:

- `actions/dependency-review-action` is now v5.0.0 (node24) — the
  "still uses node20" NOTE at the call site is outdated post-#157.
- `ludeeus/action-shellcheck@00cae500` is a composite action (no node
  runtime), so it was never affected by the node20 deprecation; the
  previous NOTE misclassified it.

Audit summary of the 12 other SHA-pinned actions: all on `node24` or
`composite` runtimes, no further action needed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@Twodragon0
Twodragon0 force-pushed the chore/node20-cleanup-gitleaks-cli branch from 125dc2d to c236fb7 Compare May 21, 2026 03:36
@Twodragon0
Twodragon0 merged commit d7feff6 into main May 21, 2026
24 checks passed
@Twodragon0
Twodragon0 deleted the chore/node20-cleanup-gitleaks-cli branch May 21, 2026 03:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants