leakless the gatepackage evidence / README + Action / read 2026-09-25
LIVE URL, BUILD GATE
READ 2026-09-25
Read the Action0 runtime dependencies1 request per run3 exit codes2 named failure paths90 second default timeoutVERSION 0.1.0SCROLL RIGHT FOR MORE
GITHUB ACTION / DEPLOYED URL
A GitHub Action that scans a deployed URL with BreachProbe and fails the build on an exposed database or an open write path.
A green test suite proves what its own tests expect. The running system is a different property.
SAMPLE OUTPUT / DEFAULT GATEREAD FROM README
Scanned example.com: 7171 /100, grade C.
A few hardening gaps. No open door we could walk through, but
THE SAMPLE IS THE README OUTPUT. A LIVE RUN WRITES ITS OWN REPORT.
CONTRACTONE SCAN / NO LOOP
What the Action reads from the running system
INPUTMEANINGDEFAULT
urlThe deployed URL to scan.requiredowner-confirmedLiteral true, for a URL you own or are authorised to scan.requiredmin-gradeFail when the scan grade is at or below this.FtimeoutSeconds to wait before the run becomes exit 2.90SCROLL RIGHT FOR MORE INPUTS
THE RUNONE REQUEST
One scan per run.
01Scan a deployed URL with BreachProbe.
02Read the score, grade, and findings.
03Return 0, 1, or 2. A failed request is exit 2, not a second attempt.
SOURCES22 CLAIMS RE-READ
Every sentence above comes from the package.
README / purposeA GitHub Action that scans a deployed URL with BreachProbe and fails the build on an exposed database or an open write path.README / whyA green test suite proves the code you wrote compiles and does what its own tests expect.README / whyThat is a property of the running system, not of the source, and nothing else in CI checks it.README / rate limitsOne scan per run.README / rate limitsthis never retries and never polls: a request that fails is exit 2, not a second attempt.action.yml / ownerMust be the literal string "true".README / inputsFail when the scan grade is at or below this.README / inputsSeconds to wait on the scan before the run becomes exit 2.README / exit codes2 covers an unreachable target as much as a BreachProbe outage.README / named conditionAn exposed database is a category: database finding at high or critical severity.README / named conditionAn open write path is a leaked service_role or secret key, or a row-level-security policy that does not enforce tenant isolation.README / limitationThis scans what is live right now, not the code in the pull request.README / limitationThe free scan does not run BreachProbe's authenticated cross-tenant probe.package.json / enginesnode: >=18package.json / dependenciesdependencies: {}package.json / licenselicense: MITREADME / licenceMIT. Built and used in production by Compound Labs.README / outputsThe scan score, 0 to 100, empty when unreachable.README / exit codes0 reachable, and neither named condition was foundREADME / exit codes1 an exposed database, an open write path, or the grade floor was crossedREADME / exit codes2 the gate could not run. Not a pass, and it never collapses into 0README / local useNo build step, no bundler, zero runtime dependencies.