Skip to content

ci(secret-scan): canonical estate scanner caller, key scan (D243) - #41

Merged
hyperpolymath merged 2 commits into
mainfrom
ci/secret-scan-floor-caller
Oct 1, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
ci/secret-scan-floor-caller

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

What

Write the canonical estate secret-scanner caller to .github/workflows/secret-scanner.yml so this repo emits scan / gitleaks, the context the estate Secret-Scan-Floor ruleset (D243/D244) requires. This repo had no secret-scanner caller.

Job key scan; reusable hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@74d2f66f575246cf6e313ae7775f44df6e097ff2; push trigger on main. actionlint clean (previous file findings: n/a). Commit via GraphQL createCommitOnBranch (GitHub-signed, valid: true).

🤖 Generated with Claude Code

https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK

Secret-Scan-Floor (D243/D244) requires the context `scan / gitleaks` estate-wide. This repo had no secret-scanner caller. Write the canonical caller: job key `scan`, reusable pinned to standards@74d2f66, push trigger on the default branch `main`.

actionlint: new file clean (findings in previous file: n/a).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 49 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 0fe2caef-335a-4377-9723-3114ccbb5bbf

📥 Commits

Reviewing files that changed from the base of the PR and between 039182f and 8fd849f.

📒 Files selected for processing (1)
  • .github/workflows/secret-scanner.yml

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 00bcb081-c64f-49da-b617-3d6bb4062926

📥 Commits

Reviewing files that changed from the base of the PR and between 2f28407 and 039182f.

📒 Files selected for processing (1)
  • .github/workflows/secret-scanner.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (7)
  • GitHub Check: scan / gitleaks
  • GitHub Check: scan / shell-secrets
  • GitHub Check: hypatia / Hypatia Neurosymbolic Analysis
  • GitHub Check: check-banned-languages
  • GitHub Check: lint
  • GitHub Check: analyze (javascript-typescript, none)
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (1)
.github/workflows/secret-scanner.yml (1)

1-27: LGTM!


📝 Summary

Summary by CodeRabbit

  • Chores
    • Added automated secret scanning for pull requests and pushes to the main branch.

Walkthrough

The pull request adds a GitHub Actions workflow that runs a pinned reusable secret scanner on pull requests and pushes to main. The workflow sets read-only contents permission, inherits secrets, and cancels in-progress runs for matching workflow and ref.

Changes

Secret scanning

Layer / File(s) Summary
Configure the secret-scanner workflow
.github/workflows/secret-scanner.yml
Adds pull-request and main push triggers, concurrency cancellation, read-only contents permission, and a scan job that calls the pinned reusable workflow with inherited secrets.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 03918

The workflow is configured to request the required scan / gitleaks check on pull requests and main pushes. No concrete merge-blocking risk remains, though actual run completion was not observed.

Architecture Summary

Architecture risk: 🔵 Low · up to 03918

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/secret-scanner.yml: Adds the Secret Scanner workflow, its pull-request and main push triggers, concurrency cancellation by workflow and ref, read-only contents permission, and a scan job that calls the reusable scanner at a pinned revision with inherited secrets. The comments specify the required job key and secrets inheritance.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the addition of the canonical secret-scanner caller and the scan job key. It accurately reflects the main change.
Description check ✅ Passed The description directly explains the new workflow, reusable workflow reference, trigger, job key, and intended scan / gitleaks context. It is relevant to the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the workflow's call,
And scans each pull request and push.
With secrets passed and permissions small,
It hops through runs without a rush.
On main, the scanner starts its quest,
Then curls up when a newer run is best.

Comment @coderabbitai help to get the list of available commands.

Comment thread .github/workflows/secret-scanner.yml Fixed
coderabbitai[bot]
coderabbitai Bot previously approved these changes Oct 1, 2026
… privilege)

The reusable at standards@74d2f66 references no secrets: gitleaks runs as a checksum-verified binary, not gitleaks-action, so `secrets: inherit` only forwarded every repository and organisation secret to it (CWE-250, flagged by CodeRabbit and Hypatia WH008). The earlier comment calling it REQUIRED was copied from the reusable's own stale header note and is corrected here.

actionlint clean.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
@hyperpolymath
hyperpolymath merged commit 0ed02a6 into main Oct 1, 2026
14 checks passed
@hyperpolymath
hyperpolymath deleted the ci/secret-scan-floor-caller branch October 1, 2026 14:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants