Publication Sanitization Gate

skill · created

Evidence record

What is verified
Uses in published workflows: 2
Source
Published workflow connections
Revision
Version 0.1.5
Validation status
Public-sanitized publication; no independent validation is claimed.

What this is and why

Turns the sanitization rules into an automatic, blocking CI check on every public publication path. Two detector layers work together: a version-pinned generic secret scanner and a project denylist of internal identifiers, mirrored into CI as patterns rather than values. The check fails closed, an allowlist entry requires an in-repo justification with an expiry, and the gate is mutation-proven: a planted forbidden token must turn CI red, because a gate that has never been red proves nothing.

Relations

Neighbor diagram: this capability’s direct relations in the knowledge graph uses uses selects uses part-of derived-from projection-pipeline repo-provisioning-sanitiz… talo-0024-workflow0-evide… stage-1-repos repo-provisioning-sanitiz… sanitized-projection Publication Sanitization Gate
Uses: derived-from
sanitized-projection
Uses: part-of
repo-provisioning-sanitized
Used by: uses
projection-pipelinerepo-provisioning-sanitizedstage-1-repos
Required by: selects
talo-0024-workflow0-evidence

Show this capability and its neighbours in the catalog

Metadata and provenance

id
tal-skill-sanitization-gate
type
skill
version
0.1.5
origin
created in Talomnia
lifecycle
public_sanitized
tags
security, tz-3-3, ci

The source is the private knowledge repository; only the sanitized public projection reaches this site.

verified · tal-skill-sanitization-gate · v0.1.5