ci(secret-scan): canonical estate scanner caller, key scan (D243) - #36
Conversation
Secret-Scan-Floor (D243/D244) requires the context `scan / gitleaks` estate-wide. The previous caller pinned a reusable that no longer resolves (or the file was invalid), so the scanner never ran. Write the canonical caller: job key `scan`, reusable pinned to standards@74d2f66, push trigger on the default branch `main`. actionlint: new file clean (findings in previous file: 6). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (13)
|
| Layer / File(s) | Summary |
|---|---|
Document and configure secret scanning .github/workflows/secret-scanner.yml |
Comments describe the workflow’s role, required scan check-context key, and secret inheritance requirement. The reusable workflow reference changed, and the caller-level permissions block was removed. |
Priority: ➖ Normal
Estimated code review effort: 2 (Simple) | ~8 minutes
Change: Bug fix
Suggested reviewers: metadatastician
Merge Risk: ⚪ Minimal · up to cfbb7
The secret scan runs for pull requests and supplies the required check. No merge-blocking issue was established.
Architecture Summary
Architecture risk: 🔵 Low · up to cfbb7
The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.
Changed systems: None identified.
Architecture concerns
No architecture-level concerns identified.
Review details
Before / after behavior
- observed — Modified behavior in .github/workflows/secret-scanner.yml: Added comments describing the workflow's secret-scanning role, the required
scancheck-context key, and the requirement to inherit secrets for the scanner's token. - observed — Modified behavior in .github/workflows/secret-scanner.yml: The
scanjob now references reusable workflow commit74d2f66f575246cf6e313ae7775f44df6e097ff2instead ofc65436ee3351cd6b0fa14b142938b195efc77586; the caller-level permissions block grantingcontents: read,pull-requests: writeandactions: readwas removed.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
| Check name | Status | Explanation |
|---|---|---|
| Docstring Coverage | ✅ Passed | No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0… |
| Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Title check | ✅ Passed | The title clearly identifies the main change: the canonical secret-scanner caller and the required scan job key. |
| Description check | ✅ Passed | The description directly explains the workflow change, reusable workflow reference, trigger, expected scanner context, and reason for the update. |
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
- Commit to this branch
- Create a new PR
- Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts
Autopilot is currently an internal CodeRabbit preview.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
A rabbit checks the scanner’s trail,
And notes the secrets it must hail.
The scan job takes a newer route,
Old permissions leave the loop.
With careful paws, the workflow’s clear,
A tidy check for all to cheer.
Comment @coderabbitai help to get the list of available commands.
… privilege) The reusable at standards@74d2f66 references no secrets: gitleaks runs as a checksum-verified binary, not gitleaks-action, so `secrets: inherit` only forwarded every repository and organisation secret to it (CWE-250, flagged by CodeRabbit and Hypatia WH008). The earlier comment calling it REQUIRED was copied from the reusable's own stale header note and is corrected here. actionlint clean. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
What
Write the canonical estate secret-scanner caller to
.github/workflows/secret-scanner.ymlso this repo emitsscan / gitleaks, the context the estate Secret-Scan-Floor ruleset (D243/D244) requires. The previous caller pinned a reusable that no longer resolves (or the file was invalid), so the scanner never ran.Job key
scan; reusablehyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@74d2f66f575246cf6e313ae7775f44df6e097ff2; push trigger onmain. actionlint clean (previous file findings: 6). Commit via GraphQLcreateCommitOnBranch(GitHub-signed, valid: true).🤖 Generated with Claude Code
https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
Deferred red checks
governance / Guix primary / Nix fallback policy→ CI: 1 red check(s) on the default branch, deferred from #36 #37