ci(secret-scan): canonical estate scanner caller, key scan (D243) - #83
Conversation
Secret-Scan-Floor (D243/D244) requires the context `scan / gitleaks` estate-wide. The previous inline scanner jobs emitted bare contexts (e.g. `gitleaks`) that cannot satisfy the floor; the reusable deliberately drops TruffleHog as redundant with gitleaks. Write the canonical caller: job key `scan`, reusable pinned to standards@74d2f66, push trigger on the default branch `main`. actionlint: new file clean (findings in previous file: 0). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 53 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (17)
🔇 Additional comments (2)
📝 SummarySummary by CodeRabbit
WalkthroughThe secret-scanner workflow replaces its local TruffleHog, Gitleaks and Rust-specific jobs with a pinned reusable workflow. It retains the pull-request and ChangesSecret scanner workflow
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~5 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to This change moves secret scanning to a pinned shared workflow that emits the required Architecture SummaryArchitecture risk: 🔵 Low · up to The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency. Changed systems: None identified. Architecture concerns Review detailsBefore / after behavior
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Description checkExplanation The description explains the purpose, workflow, reusable workflow revision, trigger, testing result, and related ruleset. However, it does not use the required Summary, Changes, RSR Quality Checklist, Testing, and Screenshots sections, and it does not provide the required checklist status.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the workflow path, Comment |
… privilege) The reusable at standards@74d2f66 references no secrets: gitleaks runs as a checksum-verified binary, not gitleaks-action, so `secrets: inherit` only forwarded every repository and organisation secret to it (CWE-250, flagged by CodeRabbit and Hypatia WH008). The earlier comment calling it REQUIRED was copied from the reusable's own stale header note and is corrected here. actionlint clean. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
What
Write the canonical estate secret-scanner caller to
.github/workflows/secret-scanner.ymlso this repo emitsscan / gitleaks, the context the estate Secret-Scan-Floor ruleset (D243/D244) requires. The previous inline scanner jobs emitted bare contexts (e.g.gitleaks) that cannot satisfy the floor; the reusable deliberately drops TruffleHog as redundant with gitleaks.Job key
scan; reusablehyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@74d2f66f575246cf6e313ae7775f44df6e097ff2; push trigger onmain. actionlint clean (previous file findings: 0). Commit via GraphQLcreateCommitOnBranch(GitHub-signed, valid: true).🤖 Generated with Claude Code
https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK