Skip to content

ci(secret-scan): canonical estate scanner caller, key scan (D243) - #78

Merged
hyperpolymath merged 2 commits into
mainfrom
ci/secret-scan-floor-caller
Oct 1, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
ci/secret-scan-floor-caller

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

What

Write the canonical estate secret-scanner caller to .github/workflows/secret-scanner.yml so this repo emits scan / gitleaks, the context the estate Secret-Scan-Floor ruleset (D243/D244) requires. The previous inline scanner jobs emitted bare contexts (e.g. gitleaks) that cannot satisfy the floor; the reusable deliberately drops TruffleHog as redundant with gitleaks.

Job key scan; reusable hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@74d2f66f575246cf6e313ae7775f44df6e097ff2; push trigger on main. actionlint clean (previous file findings: 0). Commit via GraphQL createCommitOnBranch (GitHub-signed, valid: true).

🤖 Generated with Claude Code

https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK

Secret-Scan-Floor (D243/D244) requires the context `scan / gitleaks` estate-wide. The previous inline scanner jobs emitted bare contexts (e.g. `gitleaks`) that cannot satisfy the floor; the reusable deliberately drops TruffleHog as redundant with gitleaks. Write the canonical caller: job key `scan`, reusable pinned to standards@74d2f66, push trigger on the default branch `main`.

actionlint: new file clean (findings in previous file: 0).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 147fac48-3dfc-4a77-818d-717afb578ba0

📥 Commits

Reviewing files that changed from the base of the PR and between 14f23f0 and 5e920c2.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (1)
  • .github/workflows/secret-scanner.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (3)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: hypatia / Hypatia Neurosymbolic Analysis
  • GitHub Check: semgrep-cloud-platform/scan
⚠️ CI failures not shown inline (2)

GitHub Actions: Workflow Security Linter / 0_lint-workflows.txt: ci(secret-scan): canonical estate scanner caller, key scan (D243)

Conclusion: failure

View job details

##[group]Run errors=0
 �[36;1merrors=0�[0m
 �[36;1mfor f in .github/workflows/*.yml .github/workflows/*.yaml; do�[0m
 �[36;1m  [ -f "$f" ] || continue�[0m
 �[36;1m  if ! head -1 "$f" | grep -q "SPDX-License-Identifier"; then�[0m
 �[36;1m    echo "ERROR: $f missing SPDX header"�[0m
 �[36;1m    errors=$((errors + 1))�[0m
 �[36;1m  fi�[0m
 �[36;1mdone�[0m
 �[36;1mexit $errors�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ERROR: .github/workflows/casket-pages.yml missing SPDX header
 ERROR: .github/workflows/codeql.yml missing SPDX header
 ERROR: .github/workflows/dogfood-gate.yml missing SPDX header
 ERROR: .github/workflows/governance.yml missing SPDX header
 ERROR: .github/workflows/hypatia-scan.yml missing SPDX header
 ERROR: .github/workflows/instant-sync.yml missing SPDX header
 ERROR: .github/workflows/label-triage.yml missing SPDX header
 ERROR: .github/workflows/labels.yml missing SPDX header
 ERROR: .github/workflows/mirror.yml missing SPDX header
 ERROR: .github/workflows/push-email-notify.yml missing SPDX header
 ERROR: .github/workflows/scorecard.yml missing SPDX header
 ERROR: .github/workflows/workflow-linter.yml missing SPDX header
 ##[error]Process completed with exit code 12.

GitHub Actions: Workflow Security Linter / lint-workflows: ci(secret-scan): canonical estate scanner caller, key scan (D243)

Conclusion: failure

View job details

##[group]Run errors=0
 �[36;1merrors=0�[0m
 �[36;1mfor f in .github/workflows/*.yml .github/workflows/*.yaml; do�[0m
 �[36;1m  [ -f "$f" ] || continue�[0m
 �[36;1m  if ! head -1 "$f" | grep -q "SPDX-License-Identifier"; then�[0m
 �[36;1m    echo "ERROR: $f missing SPDX header"�[0m
 �[36;1m    errors=$((errors + 1))�[0m
 �[36;1m  fi�[0m
 �[36;1mdone�[0m
 �[36;1mexit $errors�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ERROR: .github/workflows/casket-pages.yml missing SPDX header
 ERROR: .github/workflows/codeql.yml missing SPDX header
 ERROR: .github/workflows/dogfood-gate.yml missing SPDX header
 ERROR: .github/workflows/governance.yml missing SPDX header
 ERROR: .github/workflows/hypatia-scan.yml missing SPDX header
 ERROR: .github/workflows/instant-sync.yml missing SPDX header
 ERROR: .github/workflows/label-triage.yml missing SPDX header
 ERROR: .github/workflows/labels.yml missing SPDX header
 ERROR: .github/workflows/mirror.yml missing SPDX header
 ERROR: .github/workflows/push-email-notify.yml missing SPDX header
 ERROR: .github/workflows/scorecard.yml missing SPDX header
 ERROR: .github/workflows/workflow-linter.yml missing SPDX header
 ##[error]Process completed with exit code 12.
🔇 Additional comments (1)
.github/workflows/secret-scanner.yml (1)

2-10: LGTM!


📝 Summary

Summary by CodeRabbit

  • Chores
    • Secret scanning now runs through a shared workflow instead of separate checks. Scans continue to run for pull requests and pushes to the main branch, with the existing concurrency settings retained. No changes to product features or user-facing behaviour.

Walkthrough

The workflow retains its pull-request and main-branch push triggers. It replaces three local secret-scanning jobs with a scan job that calls a pinned shared workflow. The header documents the scanner and the deliberate omission of secrets:.

Changes

Secret scanning workflow

Layer / File(s) Summary
Reusable scanner integration
.github/workflows/secret-scanner.yml
The workflow documents the shared scanner, required scan check context and omission of secrets:. The scan job calls a pinned shared workflow instead of the local TruffleHog, Gitleaks and Rust pattern-check jobs.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: metadatastician

Merge Risk: ⚪ Minimal · up to 5e920

The shared scanner receives GitHub’s token without inheriting repository secrets. No concrete merge-blocking issue remains; merge after normal checks pass.

Architecture Summary

Architecture risk: 🔵 Low · up to 5e920

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/secret-scanner.yml: The workflow header replaces the repeated gh actions-lock management comments and the brief prevention description with details about the shared scanners, the required scan check context, and the deliberate omission of secrets:. The workflow name and pull-request and main-branch push triggers remain unchanged.
  • observed — Modified behavior in .github/workflows/secret-scanner.yml: The local TruffleHog, Gitleaks, and Rust secret-scanning jobs are removed and replaced by a scan job that calls the shared reusable secret-scanner workflow at a pinned revision.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the CI secret-scanner change and the canonical scanner caller. It is specific to the main change.
Description check ✅ Passed The description directly explains the workflow change, required scan context, reusable workflow, triggers, and validation results.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🛠️ Fix failing CI checks
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the scanner’s trail,
The shared workflow takes the rail.
Pull requests pass through the gate,
Main branch pushes join the slate.
No secrets field; the comments state.

Comment @coderabbitai help to get the list of available commands.

…aller

The caller's only uses: is a job-level reusable workflow, which actions.lock does
not track; the stale step entries left from the inline scanner made GitHub refuse
to start the workflow (startup_failure, jobs=0). Verified: standards
check-actions-lock-gate.sh rc=0 and gh actions-lock --no-fix valid=true.
gh actions-lock does not rewrite this key itself (D283).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
@hyperpolymath
hyperpolymath merged commit 5f0b102 into main Oct 1, 2026
31 of 33 checks passed
@hyperpolymath
hyperpolymath deleted the ci/secret-scan-floor-caller branch October 1, 2026 23:46
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Autopilot could not be updated. Open Coding to check access and billing.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Agent ran but produced no code changes.

The CI failures may require manual intervention.

View agent analysis
I haven't made any changes. The only fix is to edit CI workflow files, and the rules for this task don't allow me to modify workflows.

**Why it fails:** the linter's "Check SPDX headers" step (in `workflow-linter.yml`) requires the very first line of every workflow file to contain `SPDX-License-Identifier`. In 12 of the workflow files, the first line is now `# This workflow is managed by gh actions-lock.`, and the SPDX line has been pushed down to line 2. In some files, such as `codeql.yml`, that comment appears more than once. The 12 failures are where the exit code 12 comes from.

**This PR didn't cause it.** The PR's own file, `.github/workflows/secret-scanner.yml`, already has the SPDX header on line 1 and passes. The 12 failing files aren't in the PR's diff. They were changed by the `gh actions-lock` tool (commit 5e920c2, "ci(actions-lock): …"), which put its comment above the SPDX line.

**To fix it, someone with permission to change workflows needs to either:**
1. Move `# SPDX-License-Identifier: MPL-2.0` back to line 1 in each of the 12 files and remove the repeated actions-lock comments. This would also mean configuring `gh actions-lock` to write its comment below the SPDX line, or it will undo the fix the next time it runs.
2. Or relax the linter check in `workflow-linter.yml` to look at the first few lines instead of only `head -1`.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant