ci(secret-scan): canonical estate scanner caller, key scan (D243) - #93
Conversation
Secret-Scan-Floor (D243/D244) requires the context `scan / gitleaks` estate-wide. The previous inline scanner jobs emitted bare contexts (e.g. `gitleaks`) that cannot satisfy the floor; the reusable deliberately drops TruffleHog as redundant with gitleaks. Write the canonical caller: job key `scan`, reusable pinned to standards@74d2f66, push trigger on the default branch `main`. actionlint: new file clean (findings in previous file: 0). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (5)
|
| Layer / File(s) | Summary |
|---|---|
Shared scanner workflow .github/workflows/secret-scanner.yml |
The workflow calls a pinned shared secret-scanner reusable workflow instead of defining local TruffleHog, Gitleaks and Rust scanning jobs. It retains its triggers and concurrency settings, removes actions: read, and declares no secrets. |
Priority: ➖ Normal
Estimated code review effort: 2 (Simple) | ~10 minutes
Change: Bug fix
Merge Risk: ⚪ Minimal · up to 723dd
The secret scanner workflow now calls a pinned shared workflow and should emit the scan / gitleaks check the ruleset requires. Permissions are compatible with the caller's read-only grant. No merge-blocking risk was found.
Architecture Summary
Architecture risk: 🔵 Low · up to 723dd
The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.
Changed systems: None identified.
Architecture concerns
No architecture-level concerns identified.
Review details
Before / after behavior
- observed — Modified behavior in .github/workflows/secret-scanner.yml: The workflow replaces its local TruffleHog, Gitleaks, and Rust scanning jobs with a pinned reusable workflow call. It retains the pull-request and
mainpush triggers and concurrency cancellation, removes theactions: readpermission, and declares no secrets.
🚥 Pre-merge checks | ✅ 4 | ❌ 1
❌ Failed checks (1 warning)
| Check name | Status | Explanation | Resolution |
|---|---|---|---|
| Description check | The description explains the purpose and reports actionlint validation, but it does not follow the repository template. It omits the required Summary, Changes, RSR Quality Checklist, Testing, and Scre… | Update the description to use the repository template. Add the required Summary, Changes, RSR Quality Checklist, and Testing sections. Complete each applicable checklist item with its actual status. Add Screenshots output or state that scre… |
✅ Passed checks (4 passed)
| Check name | Status | Explanation |
|---|---|---|
| Title check | ✅ Passed | The title clearly identifies the main change: replacing the inline secret scanner with the canonical estate scanner caller. |
| Docstring Coverage | ✅ Passed | No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0… |
| Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
Full details: Description check
Explanation
The description explains the purpose and reports actionlint validation, but it does not follow the repository template. It omits the required Summary, Changes, RSR Quality Checklist, Testing, and Screenshots headings, and it does not record the required checklist results.
Resolution
Update the description to use the repository template. Add the required Summary, Changes, RSR Quality Checklist, and Testing sections. Complete each applicable checklist item with its actual status. Add Screenshots output or state that screenshots are not applicable.
- Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
- Commit to this branch
- Create a new PR
- Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts
Autopilot is currently an internal CodeRabbit preview.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
A rabbit checks the workflow’s trail
The shared scanner takes the call
No local jobs remain to run
A pinned workflow scans the change
Then hops away beneath the moon
Comment @coderabbitai help to get the list of available commands.
…aller The caller's only uses: is a job-level reusable workflow, which actions.lock does not track; the stale step entries left from the inline scanner made GitHub refuse to start the workflow (startup_failure, jobs=0). Verified: standards check-actions-lock-gate.sh rc=0 and gh actions-lock --no-fix valid=true. gh actions-lock does not rewrite this key itself (D283). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
What
Write the canonical estate secret-scanner caller to
.github/workflows/secret-scanner.ymlso this repo emitsscan / gitleaks, the context the estate Secret-Scan-Floor ruleset (D243/D244) requires. The previous inline scanner jobs emitted bare contexts (e.g.gitleaks) that cannot satisfy the floor; the reusable deliberately drops TruffleHog as redundant with gitleaks.Job key
scan; reusablehyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@74d2f66f575246cf6e313ae7775f44df6e097ff2; push trigger onmain. actionlint clean (previous file findings: 0). Commit via GraphQLcreateCommitOnBranch(GitHub-signed, valid: true).🤖 Generated with Claude Code
https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK