Skip to content

Secret-Scan-Floor (D243/D244): sweep results and open items with acceptance criteria #1108

Description

@hyperpolymath

Context

D243/D244 (owner ruling 2026-10-01) put an estate-wide Secret-Scan-Floor ruleset on every non-vault, non-fork repo whose default head emits scan / gitleaks: 336 repos (first pass: 312 created and 2 already present; second pass: 21 created and 1 already present). The 103 repos that do not yet emit the context have no floor, because a floor there would block every PR. Section 2, section 3 and the B-shape rename backlog cover them. The ruleset requires the context scan / gitleaks (integration 15368, admin-role bypass, target ~DEFAULT_BRANCH). The callers were made to emit that context by renaming the job key secret-scan → scan and by writing the canonical caller (secret-scanner-reusable.yml@74d2f66).

What landed and what is still open is recorded below. Each item that the sweep could not close is listed with acceptance criteria. Per the 09-15 standing ruling, a scanner finding is an issue, not a blocker.

Horizon: every measurement below is from the GraphQL API on 2026-10-01 between 12:00Z and 13:45Z, over the 439 repos of hyperpolymath + metadatastician that are not archived. The 3 gcrypt vaults and 5 forks were excluded by name.

1. Default branches RED at gitleaks — 31 repos (possible committed secrets)

Re-measured at each default-branch head (not the census snapshot). The gating gitleaks pass in secret-scanner-reusable.yml@74d2f66 scans the full history (fetch-depth: 0, it refuses a shallow clone, and its own comment says "The gate is full-history"). So on these repos every PR is red at scan / gitleaks too. 21 of them now carry the floor, which the owner accepted: their PRs are blocked until the finding is triaged, or merged by an admin bypass. The repos:

  • hyperpolymath/boj-server @ 0ba6a6c4

  • hyperpolymath/panic-attack @ 5ee25658

  • hyperpolymath/poly-observability-mcp @ 6fa74f22

  • hyperpolymath/panll @ 03583e9a

  • hyperpolymath/nickel-augmentation @ 77e39f76

  • hyperpolymath/lcb-website @ 345431e8

  • hyperpolymath/januskey @ fd0c56f9

  • hyperpolymath/hyperpolymath-sovereign-registry @ 89847c6a

  • hyperpolymath/hpm-crypto-rsr @ f1e42c97

  • hyperpolymath/frayed-knot-toolkit @ 07798e2a

  • hyperpolymath/laminar @ 582aa532

  • hyperpolymath/email-octad-experiment @ 5cd67a27

  • hyperpolymath/lithoglyph @ ba7ebe20

  • hyperpolymath/boj-server-cartridges @ 50b1af4c

  • hyperpolymath/contractiles-a2-lab @ 5943ae6b

  • hyperpolymath/blog-drafts @ 8c545cb2

  • hyperpolymath/007-lang @ 61054841

  • hyperpolymath/ipv6-tools @ 632bb26b

  • hyperpolymath/jtv-halting-islands-ct @ b41e29d1

  • hyperpolymath/zotero-tools @ 0a00bcfb

  • hyperpolymath/claude-memory @ 1299ac9b

  • hyperpolymath/typefix-zero @ ae598741

  • hyperpolymath/echobox @ bf6371bc

  • hyperpolymath/veridical-simulation-core @ 7b8297b3

  • hyperpolymath/jewell.nexus @ 48e66fdb

  • hyperpolymath/axel-protocol @ 9d077309

  • hyperpolymath/jonathanjewell.dev @ 56528d60

  • hyperpolymath/hpm-github-api-rsr @ 8274b3d5

  • metadatastician/insolvency-tycoon @ 4c52759a

  • metadatastician/enaction-engine @ 9165cf5d

  • metadatastician/burble @ b36f142a

  • Each repo: triage the gitleaks finding(s) on main. Either rotate and purge the secret, or add a reviewed .gitleaksignore entry naming the fingerprint and the reason.

  • scan / gitleaks (or secret-scan / gitleaks) is SUCCESS on the default-branch head.

2. Repos with actions.lock — caller not yet written (21)

The canonical caller calls hyperpolymath/standards@74d2f66…, whose job uses actions/checkout@3d3c42e5…. A lock that lacks either record startup-kills the caller. Repos: hyperpolymath/cicd-suite, hyperpolymath/marches, hyperpolymath/network-outpost, hyperpolymath/residual-evidence-types, hyperpolymath/smtp-notify-action, hyperpolymath/trigger, hyperpolymath/claude-integrations, hyperpolymath/flat-mate, hyperpolymath/kitchenspeak, hyperpolymath/knot-rider, metadatastician/common-signal, hyperpolymath/academic-workflow-suite, hyperpolymath/affinescript-vite, hyperpolymath/aspasia, hyperpolymath/bitfuckit, hyperpolymath/branch-newspaper, hyperpolymath/civic-connect, hyperpolymath/defiant, hyperpolymath/ideas-to-alphas, hyperpolymath/poly-k8s-mcp, metadatastician/proglanging-languages. proglanging-languages has an open PR (#3, the old pin @bd0df9ea with a lock missing a checkout record, so it startup-fails), which will be reworked under this item.

  • gh actions-lock gains callee-aware generation: locking a workflow that calls a reusable also records the reusable's own uses: (transitively closed).
  • Each listed repo gets the canonical caller plus lock records, verified with gh actions-lock --no-fix (not a hand-rolled check) before the PR opens.
  • The flat-mate class (callers at @84355587 with an extra inline trufflehog job and a lock missing actions/checkout@3d3c42e5) is covered by the same fix.

3. Private repos — Actions availability unproven (6)

hyperpolymath/lfs-shared, hyperpolymath/linguist, hyperpolymath/multiterm, metadatastician/bowtie-workbench, metadatastician/reflexive-ai-studio, hyperpolymath/polystack — no caller was written. If Actions cannot run (billing), a floor deadlocks every PR.

  • Each: establish whether Actions run (a workflow run on the default head in the last 30 days), then either write the caller or record an exemption.

4. Phantom and dead reusable pins

  • metadatastician/common-signal: secret-scanner.yml pins @5b1d0022, which does not exist in hyperpolymath/standards ("failed to fetch workflow"). Its lock entry for the file is [].
  • Pins @892497fe and @7fdc2705 fail with "error parsing called workflow … workflow was not found".
  • A lock/pin validator rejects a reusable SHA that does not resolve in the callee repo (shape-checked: 40 hex characters and the object exists).

5. Rulesets that already require the OLD context — irreversible-cutover shape

epistemic-types (secret-scan / gitleaks), deed-ecosystem (secret-scan / gitleaks, rust-secrets, shell-secrets), firmboot (firmboot-continuity-proof-branch requires secret-scan / gitleaks). Renaming the key here deadlocks every PR until the ruleset changes.

  • Owner decision per repo. The shim is: open the rename PR, updateRepositoryRuleset swapping the contexts to scan / …, then merge.

6. Invalid caller files (never ran)

6a. Startup failures unrelated to the caller (17 INSPECT rows)

  • "Actor is not allowed to trigger Actions workflows": aerie, docudactyl, iseriser, occupancy-types, proven. Every head suite startup-fails, so no scanner context ever lands.
  • "Invalid lockfile": awesome-idris2, cafescripto, eclexia, lucidscript, social-media-tools, universal-chat-extractor. The lock must be repaired before the caller can be bumped or replaced.
  • No scanner suite on head after a dependabot bump: dictask, first-post.
  • the-nash-equilibrium (guard-defective, do not merge) and affinescript (a deliberately inline scan job that emits a bare scan) were left alone on purpose.
  • Each: the cause is identified, and scan / gitleaks reports on the default head.

6b. The reusable's header still says secrets: inherit is REQUIRED — false at @74d2f66

.github/workflows/secret-scanner-reusable.yml lines 32-35 tell callers to pass secrets: inherit, or else "the gitleaks action's inner secrets.GITHUB_TOKEN is empty". At 74d2f66 the reusable has no ${{ secrets.* }} reference, and gitleaks runs as a checksum-verified binary (line 45 says it replaced gitleaks/gitleaks-action). So secrets: inherit only forwards every repo and org secret to it (CWE-250). CodeRabbit (oikosbot-estate#3) and Hypatia WH008 (launch-scaffolder#68) both flagged it.

This sweep's caller template copied the false note. It was corrected in all 26 caller PRs and in zerostep#102, each by a second signed commit. Positive control: zerostep#102 went green on all three scan / jobs with no secrets passed.

  • The reusable's header drops the secrets: inherit instruction and says the caller needs no secrets: line.
  • Existing callers that still pass secrets: inherit to this reusable are listed and dropped (a census keyed on content).

6c. New caller PRs RED at gitleaks (4)

These PRs only add or replace the caller file. Their scan / gitleaks is FAILURE on the PR head. The gating pass scans the full history, so the finding is almost certainly pre-existing history these repos had never scanned, not the PR diff (triage pending): hyperpolymath/ambientops#381, hyperpolymath/palimpsest-license#161, metadatastician/project-ovine#34, hyperpolymath/misinformation-defence-platform#85. Each repo's default branch had no running scanner before (ADD/BUMP/REPLACE), so this is likely the first scan these repos have had.

  • Each: the finding is triaged (rotate and purge, or a reviewed .gitleaksignore entry), and the PR goes green and lands.

6d. Caller PRs BLOCKED by non-check rules (7)

All 7 have scan / gitleaks = SUCCESS. Each is blocked by another rule type:

  • oikosbot-estate#3: CodeRabbit CHANGES_REQUESTED. The thread (remove secrets: inherit) was fixed and resolved, and the review now needs re-evaluation or dismissal.
  • ci(secret-scan): canonical estate scanner caller, key scan (D243) metadatastician/authority-watch#5: code-owner review, CODE_SCANNING, and COPILOT_CODE_REVIEW (EstateBranching).
  • JuliaPackage-Reuse-Audit.jl#66, live-files#61, MacroPower.jl#30, megadog#74, neural-foundations#99: blocked by a non-check rule.
  • Each: the blocking rule type is named from rules/branches/{base}, then satisfied or waived by the owner.

7. Default branch ≠ trigger branch

HOL (default develop, trigger [main, master]) and rescript (default ci/burn-reduction-triggers-concurrency). No scanner context ever lands on the default branch.

  • The canonical caller's push trigger names the repo's actual default branch; a census flags mismatches.

8. Tooling/process defects found during the sweep

  • apps-ack-gate fails OPEN under the REST secondary limit. During a REST secondary 403 (core rate_limit reading 5000 remaining, 0 used), the enumerator returned {"error":"cannot read … pulls/N"} with rc=0. The hook's bail() then allowed the merge on its first call, with no ack table. 8 merges ran without App enumeration: hyperpolymath/bebop-ffi#82, hyperpolymath/awesome-agda#8, hyperpolymath/info#15, hyperpolymath/trope-checker#96, hyperpolymath/trope-particularity-workbench#73, hyperpolymath/awesome-haskell#14, hyperpolymath/ai-cli-lab#12, hyperpolymath/cut-calculus#12. All 8 landed GitHub-signed; post-hoc enumeration: pending: the REST secondary limit was still active at 13:18Z. Results will be posted as a comment on this issue..
    • The hook fails CLOSED (deny, with a visible reason) when it cannot enumerate. A deny is recoverable; a silent pass is not.
    • The enumerator exits non-zero on an error body (shape-check the response, not just rc).
  • rate_limit cannot see the secondary limit. Any pacing that reads core.remaining will keep hammering.
    • Pacing keys on the 403 body / retry-after, not on rate_limit.
  • Census NOFILE label keyed on filename mislabelled flat-mate (secret-scan.yml) and firmboot (secrets.yml) as having no caller.
    • The census keys on content (secret-scanner-reusable.yml@), not on the filename.
  • Automerge does not re-fire after a ruleset-only change. A PR whose blocking rule is removed stays armed and unmerged until a new event.
    • Documented; sweeps re-evaluate armed PRs after a ruleset edit.

Landed in this sweep

🤖 Generated with Claude Code

https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions