Skip to content

ci(secret-scan): canonical estate scanner caller, key scan (D243) - #83

Merged
hyperpolymath merged 2 commits into
mainfrom
ci/secret-scan-floor-caller
Oct 1, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
ci/secret-scan-floor-caller

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

What

Write the canonical estate secret-scanner caller to .github/workflows/secret-scanner.yml so this repo emits scan / gitleaks, the context the estate Secret-Scan-Floor ruleset (D243/D244) requires. The previous inline scanner jobs emitted bare contexts (e.g. gitleaks) that cannot satisfy the floor; the reusable deliberately drops TruffleHog as redundant with gitleaks.

Job key scan; reusable hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@74d2f66f575246cf6e313ae7775f44df6e097ff2; push trigger on main. actionlint clean (previous file findings: 0). Commit via GraphQL createCommitOnBranch (GitHub-signed, valid: true).

🤖 Generated with Claude Code

https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK

Secret-Scan-Floor (D243/D244) requires the context `scan / gitleaks` estate-wide. The previous inline scanner jobs emitted bare contexts (e.g. `gitleaks`) that cannot satisfy the floor; the reusable deliberately drops TruffleHog as redundant with gitleaks. Write the canonical caller: job key `scan`, reusable pinned to standards@74d2f66, push trigger on the default branch `main`.

actionlint: new file clean (findings in previous file: 0).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 53 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 2780db72-8508-4847-a7ca-52b449583a39

📥 Commits

Reviewing files that changed from the base of the PR and between 1274eb4 and e3c888f.

📒 Files selected for processing (1)
  • .github/workflows/secret-scanner.yml

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: c4f517fa-4154-42dc-a8d8-f90b8363ccb9

📥 Commits

Reviewing files that changed from the base of the PR and between 29850e4 and 1274eb4.

📒 Files selected for processing (1)
  • .github/workflows/secret-scanner.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (17)
  • GitHub Check: scan / shell-secrets
  • GitHub Check: scan / rust-secrets
  • GitHub Check: scan / gitleaks
  • GitHub Check: governance / Workflow security linter
  • GitHub Check: governance / Licence consistency
  • GitHub Check: governance / Code quality + docs
  • GitHub Check: governance / Exemption ratchet
  • GitHub Check: governance / Security policy checks
  • GitHub Check: governance / Allowlist Preflight
  • GitHub Check: governance / Debt ratchet
  • GitHub Check: governance / Trusted-base reduction policy
  • GitHub Check: governance / Language / package anti-pattern policy
  • GitHub Check: governance / Guix packaging policy (Nix retired)
  • GitHub Check: governance / Check Workflow Staleness
  • GitHub Check: analyze (actions, none)
  • GitHub Check: Hypatia Neurosymbolic Analysis
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (2)
.github/workflows/secret-scanner.yml (2)

2-9: LGTM!


24-27: 🩺 Stability & Availability

No additional pull-requests permission is required.

The pinned reusable workflow declares contents: read for its workflow and each job. Its scan jobs use checkout and local scanning only; they do not request pull-requests: read or pull-requests: write. The caller's contents: read permission therefore covers the reusable workflow's declared needs.


📝 Summary

Summary by CodeRabbit

  • Chores
    • Automated secret scanning continues to run for pull requests and updates to the main branch. The checks now use a shared scanning workflow instead of separate locally configured scanners; this does not change the application’s visible behaviour.

Walkthrough

The secret-scanner workflow replaces its local TruffleHog, Gitleaks and Rust-specific jobs with a pinned reusable workflow. It retains the pull-request and main-branch push triggers, cancellation of superseded runs and read-only contents permission.

Changes

Secret scanner workflow

Layer / File(s) Summary
Shared scanner invocation
.github/workflows/secret-scanner.yml
The workflow documentation describes the shared scanner and its requirements. The scan job invokes the pinned reusable workflow and inherits secrets. The three local scanner jobs and their scan-specific configuration are removed.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 1274e

This change moves secret scanning to a pinned shared workflow that emits the required scan / gitleaks check. No concrete defect was found, so it is ready to merge.

Architecture Summary

Architecture risk: 🔵 Low · up to 1274e

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/secret-scanner.yml: The workflow documentation now describes the shared scanner, the required scan job key and the need to inherit secrets.
  • observed — Modified behavior in .github/workflows/secret-scanner.yml: The three local scanner jobs—TruffleHog, Gitleaks and the Rust-specific pattern check—are removed and replaced by a call to the pinned reusable workflow. The new scan job inherits secrets; the removed jobs’ checkout steps, timeouts and scan-specific configuration no longer appear in this workflow.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the purpose, workflow, reusable workflow revision, trigger, testing result, and related ruleset. However, it does not use the required Summary, Changes, RSR Quality Checklist,… Rewrite the description using the repository template. Add Summary, Changes, RSR Quality Checklist, Testing, and Screenshots sections. Mark each applicable checklist item and state the test commands or results.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: replacing the secret scanner with the canonical estate scanner caller and referencing D243.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Explanation

The description explains the purpose, workflow, reusable workflow revision, trigger, testing result, and related ruleset. However, it does not use the required Summary, Changes, RSR Quality Checklist, Testing, and Screenshots sections, and it does not provide the required checklist status.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the workflow path,
The shared scanner takes its task.
Old scan jobs hop away,
Secrets pass as set today.
The main branch keeps its place,
And pull requests join the race.

Comment @coderabbitai help to get the list of available commands.

Comment thread .github/workflows/secret-scanner.yml Fixed
… privilege)

The reusable at standards@74d2f66 references no secrets: gitleaks runs as a checksum-verified binary, not gitleaks-action, so `secrets: inherit` only forwarded every repository and organisation secret to it (CWE-250, flagged by CodeRabbit and Hypatia WH008). The earlier comment calling it REQUIRED was copied from the reusable's own stale header note and is corrected here.

actionlint clean.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
@hyperpolymath
hyperpolymath merged commit 421accf into main Oct 1, 2026
25 checks passed
@hyperpolymath
hyperpolymath deleted the ci/secret-scan-floor-caller branch October 1, 2026 14:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants