Repository Tree Publication Leak Gate for Static Hosts
Pricing
from $10.00 / 1,000 repository snapshot loadeds
Repository Tree Publication Leak Gate for Static Hosts
Find repository files outside the publish directory that your live static site serves.
Pricing
from $10.00 / 1,000 repository snapshot loadeds
Rating
0.0
(0)
Developer
kingii98
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
14 hours ago
Last modified
Categories
Share
This Actor finds repository files that your live static site serves but should not. It takes the file list of your repository. It sends requests to your origin for each file outside the publish directory. Where possible, it proves that the served file is the repository file. It compares the git blob SHA-1 hash.
Input
| Field | Meaning |
|---|---|
origin | HTTPS URL of the deployed site. Private and reserved addresses are rejected. |
ownershipAttested | You must tick this box to confirm that you own the origin. Default is false. Without it, the Actor sends no request to the origin. |
githubRepo | Optional. owner/name@ref of a public repository. The Actor loads the file list with one call to the GitHub git trees API (recursive=1). It ignores pathList when you set this field. |
githubToken | Optional secret. A read-only token. It raises the GitHub rate limit. |
pathList | Optional. Repository-relative paths, for example from git ls-files. |
publishDir | Paths inside this directory are expected to be public. |
allowPublicPaths | Glob patterns for paths that are public on purpose, for example CNAME. A pattern without / also matches the file name at any depth. |
maxPaths | Default 2000. Hard cap 10000. |
Empty input {} succeeds. Because ownershipAttested defaults to false, an empty-input run sends no request to the origin. It writes a summary with gate = fail and a reason. It does not end FAILED.
How a path is checked
- Paths inside
publishDiror that matchallowPublicPathsget the verdictexpected_public. The Actor does not request them. - For each other path, the Actor sends one
HEADrequest. It usesGETif the origin answers 405 or 501. - If the status is 200, the Actor downloads at most 1 MB with
GET. - If the repository snapshot gives a blob SHA, the Actor compares it with the SHA-1 of the served bytes (
blob <size>\0<bytes>).- Match:
servedBlobShaMatches=true, verdictexposed. - No match:
servedBlobShaMatches=false, verdictnot_served. The origin probably returns a catch-all page. - No SHA (
pathList) or body larger than 1 MB:servedBlobShaMatches=unknown, verdictexposed.
- Match:
- Other results give the verdict
not_served.
The Actor follows at most 3 redirects. It follows only redirects to the same HTTPS host.
Output
The dataset has one item per path (recordType = path) with: repoPath, probedUrl, httpStatus, contentType, bytes, servedBlobShaMatches, riskClass, verdict.
The last dataset item is the summary (recordType = summary). The same record is in the key-value store under SUMMARY.
The summary has gate (pass or fail), reason, exposedCount, exposedByRiskClass, and firstExposedPaths (first 20).
A failed gate, an unreachable target, a bad input, and zero findings are results. The run still ends SUCCEEDED.
The gate is fail when a path is exposed or when the Actor could not finish the check (see reason).
Pricing events (pay per event)
| Event | When the Actor charges |
|---|---|
repository-snapshot-loaded | Once, after the GitHub tree loads and parses. Not charged for pathList. |
path-probed | Once for each path that the Actor probes on the origin. Paths with the verdict expected_public are not probed and not charged. |
If the charge limit is reached, the Actor stops. It sets gate = fail with a reason.
Limits
- The Actor does not detect a catch-all origin (single-page app) when no blob SHA is available. Use
githubRepofor hash proof. - The check of the origin address happens before the requests. It does not stop DNS rebinding.
- GitHub unauthenticated limit is 60 requests per hour per IP. Use
githubTokenorpathList. - If GitHub marks the tree as truncated, the summary notes it.
- The Actor uses HTTP only. It uses no browser, proxy, or LLM.
Development
uv run pytestuv run ruff check .