From d952d1a975f4b09e1627f0ffedb0cc859308c87f Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 17 Sep 2026 19:46:48 +0000 Subject: [PATCH] fix(ci): secret-scanner remediation text no longer cites the leak site (closes #800) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The shell-secrets job's remediation message pointed developers at avow-protocol/deploy-repos.sh — the exact file whose leak created this gate (cited twice in this same file's comments as the failure case), and a path removed by #161, so the guidance 404s. Adopt the issue's suggested text: instruct env-sourcing with an inline example and no named file — any named example can rot the same way. --- .github/workflows/secret-scanner-reusable.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/secret-scanner-reusable.yml b/.github/workflows/secret-scanner-reusable.yml index 99e493aed..15e7be6ca 100644 --- a/.github/workflows/secret-scanner-reusable.yml +++ b/.github/workflows/secret-scanner-reusable.yml @@ -792,6 +792,6 @@ jobs: done if [ $found -eq 1 ]; then - echo "::error::Hardcoded secret detected in a shell script. Source from env (see avow-protocol/deploy-repos.sh) instead." + echo "::error::Hardcoded secret detected in a shell script. Read the value from the environment (e.g. \"\${MY_TOKEN:?}\") and supply it via a repo or org secret." exit 1 fi