ci(secret-scan): rename caller job key secret-scan -> scan (D243) - #14
Conversation
Secret-Scan-Floor (D243/D244) requires the context `scan / gitleaks` estate-wide. The caller job key here was `secret-scan`, which emits `secret-scan / gitleaks` and can never satisfy the floor. Rename only; the reusable pin and permissions are unchanged. actionlint output identical before and after. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (15)
|
| Layer / File(s) | Summary |
|---|---|
Rename workflow job .github/workflows/secret-scanner.yml |
The workflow job ID changed from secret-scan to scan. The reusable workflow call and configuration remain unchanged. |
Priority: ⬇️ Low
Estimated code review effort: 1 (Trivial) | ~2 minutes
Change: Bug fix
Merge Risk: ⚪ Minimal · up to c17a6
The rename produces the required scan / gitleaks check context without affecting the scanner configuration or tracked workflow dependencies.
Architecture Summary
Architecture risk: 🔵 Low · up to c17a6
The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.
Changed systems: None identified.
Architecture concerns
No architecture-level concerns identified.
Review details
Before / after behavior
- observed — Modified behavior in .github/workflows/secret-scanner.yml: Renamed the workflow job ID from
secret-scantoscan; its reusable workflow call and configuration remain unchanged.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
| Check name | Status | Explanation |
|---|---|---|
| Title check | ✅ Passed | The title clearly identifies the CI job-key rename from secret-scan to scan. |
| Description check | ✅ Passed | The description directly explains the job-key rename and its required check-context change. |
| Docstring Coverage | ✅ Passed | No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0… |
| Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
- Commit to this branch
- Create a new PR
- Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts
Autopilot is currently an internal CodeRabbit preview.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
A rabbit spots a name change in the workflow’s row.
“From secret-scan to scan,” says the rabbit, “off we go!”
The reusable call stays just the same.
No other settings join the game.
The rabbit hops along, pleased with the tidy name.
Comment @coderabbitai help to get the list of available commands.
…ate (#16) ## Issue Closes the downstream half of #15 (2 red checks on the default branch, deferred from #14). ## Diagnosis (both checks, at source) 1. `Governance / governance / Code quality + docs` — `Check documentation` fails with **`Missing required documentation: CONTRIBUTING`**. The gate (`hyperpolymath/standards` `scripts/check-docs-presence.sh`) split README/LICENSE (blocking immediately) from CONTRIBUTING (warn until 2026-08-21, then blocking). The cutoff has passed; this repo never carried a CONTRIBUTING, so the red is genuine and this PR is the whole fix. 2. `Governance / governance / Guix packaging policy (Nix retired)` — `Package policy violation: no packaging found.` The old script demanded packaging of **every** repo. The owner ruling of 2026-10-01 (landed upstream as hyperpolymath/standards#1120 at 22:30Z, **10 h after** the red run 36863734189 timestamped 12:43Z) retires that: packaging is now gated on the repo's `rsr-profile` declaring `reproducible-build` or `container`. This repo is a build-less curated list with no profile ⇒ *not applicable*, deliberately neutral — satisfying acceptance criterion 2's "linked change with its reason". No fake `guix.scm` stub is added; the script flags stubs as violations. The reasoning is recorded at source in the new CONTRIBUTING. ## Changes - Adds `CONTRIBUTING.adoc` at the repo root — AsciiDoc per estate doc policy, one of the paths the gate accepts and GitHub auto-discovers. Content mirrors `GOVERNANCE.adoc` (licensing, review rules) and `MAINTAINERS`, documents the awesome-list entry conventions of `README.adoc`, the CI contract, and the packaging-policy non-applicability rationale. - No workflow, pin, lockfile or README change — `actions.lock`, the SHA pin of `governance-reusable.yml`, and every other gate are untouched. ## Local pre-run of the exact gate scripts - `check-docs-presence.sh .` → `✅ Core documentation present (README, LICENSE, CONTRIBUTING)` (exit 0; was exit 1 before this PR) - `check-package-policy.sh .` (in the CI's script-only shape, resolver absent) → `✅ Packaging not applicable` (exit 0) - `check-licence-consistency.sh .` → exit 0 (unchanged) - `check-trusted-base.sh .` → exit 0 (unchanged) - R5b version-string drift scan over root `\*.adoc`/`\*.md`: clean - Editor hygiene on the new file: LF, no trailing whitespace, final newline 🤖 Generated with [Claude Code](https://claude.com/claude-code) via Arena Agent Mode --------- Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
What
Rename the secret-scanner caller job key
secret-scan→scanin.github/workflows/secret-scanner.yml, so the check context becomesscan / gitleaks— the context the estate Secret-Scan-Floor ruleset (D243/D244) requires. One-line change; reusable pin, triggers and permissions unchanged. actionlint output is identical before and after.Commit created via GraphQL
createCommitOnBranch(GitHub-signed, signature valid: true).🤖 Generated with Claude Code
https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
Deferred red checks
Governance / governance / Guix packaging policy (Nix retired)→ CI: 2 red check(s) on the default branch, deferred from #14 #15Governance / governance / Code quality + docs→ CI: 2 red check(s) on the default branch, deferred from #14 #15