Skip to content

ci(secret-scan): canonical estate scanner caller, key scan (D243) - #68

Merged
hyperpolymath merged 2 commits into
mainfrom
ci/secret-scan-floor-caller
Oct 1, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
ci/secret-scan-floor-caller

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

What

Write the canonical estate secret-scanner caller to .github/workflows/secret-scanner.yml so this repo emits scan / gitleaks, the context the estate Secret-Scan-Floor ruleset (D243/D244) requires. This repo had no secret-scanner caller.

Job key scan; reusable hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@74d2f66f575246cf6e313ae7775f44df6e097ff2; push trigger on main. actionlint clean (previous file findings: n/a). Commit via GraphQL createCommitOnBranch (GitHub-signed, valid: true).

🤖 Generated with Claude Code

https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK

Secret-Scan-Floor (D243/D244) requires the context `scan / gitleaks` estate-wide. This repo had no secret-scanner caller. Write the canonical caller: job key `scan`, reusable pinned to standards@74d2f66, push trigger on the default branch `main`.

actionlint: new file clean (findings in previous file: n/a).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 7 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 01d17ccb-1c89-49f9-9aff-9ee1045eb9fd

📥 Commits

Reviewing files that changed from the base of the PR and between 2cb0f24 and bedab31.

📒 Files selected for processing (1)
  • .github/workflows/secret-scanner.yml
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread .github/workflows/secret-scanner.yml Fixed
… privilege)

The reusable at standards@74d2f66 references no secrets: gitleaks runs as a checksum-verified binary, not gitleaks-action, so `secrets: inherit` only forwarded every repository and organisation secret to it (CWE-250, flagged by CodeRabbit and Hypatia WH008). The earlier comment calling it REQUIRED was copied from the reusable's own stale header note and is corrected here.

actionlint clean.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
@hyperpolymath
hyperpolymath merged commit 03ac343 into main Oct 1, 2026
27 of 28 checks passed
@hyperpolymath
hyperpolymath deleted the ci/secret-scan-floor-caller branch October 1, 2026 14:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants