ci(secret-scanner): call estate reusable as job scan (D243 floor) - #62
Conversation
The estate-wide Secret-Scan-Floor ruleset (D243) requires the check context `scan / gitleaks`. This caller ran inline trufflehog/gitleaks/ rust-secrets jobs and emitted bare `gitleaks`, so no PR here could satisfy the floor. Replace them with the shared reusable at 74d2f66 (gitleaks + rust-secrets + shell-secrets); trufflehog is retired, as the reusable dropped it as redundant with gitleaks. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (11)
🔇 Additional comments (1)
📝 SummarySummary by CodeRabbit
WalkthroughThe secret-scanner workflow replaces its inline TruffleHog, Gitleaks and Rust-specific jobs with a pinned reusable scanner workflow. The workflow name, triggers, concurrency cancellation and read-only contents permissions remain unchanged. ChangesSecret scanning
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The workflow delegates secret scanning to the pinned shared implementation while preserving its triggers and read-only permissions. It is ready to merge subject to normal CI checks. Architecture SummaryArchitecture risk: 🔵 Low · up to The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency. Changed systems: None identified. Architecture concerns Review detailsBefore / after behavior
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Description checkExplanation The description explains the purpose and implementation, but it does not follow the repository template. It omits the required Summary, Changes, RSR Quality Checklist, Testing, and Screenshots sections, and it does not record the required checklist results.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the scanner’s call, Comment |
| fi | ||
| scan: | ||
| uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@74d2f66f575246cf6e313ae7775f44df6e097ff2 | ||
| secrets: inherit |
🔍 Hypatia Security ScanFindings: 80 issues detected
View findings[
{
"reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": "label-triage.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "triage"
},
{
"reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": "labels.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "sync"
},
{
"line": 38,
"reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 44,
"reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/push-email-notify.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 82,
"reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 52,
"reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 24,
"reason": "job in .github/workflows/mirror.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/mirror.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 44,
"reason": "job in .github/workflows/mirror.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/mirror.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 64,
"reason": "job in .github/workflows/mirror.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/mirror.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 84,
"reason": "job in .github/workflows/mirror.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/mirror.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
Why
The estate-wide Secret-Scan-Floor ruleset (owner ruling D243, ruleset
24276941on this repo) requires the status-check contextscan / gitleakson the default branch. This caller ran inline jobs and emitted a baregitleakscontext, so no PR here could satisfy the floor.Change
trufflehog,gitleaksandrust-secretsjobs are replaced by one call tohyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@74d2f66(the latest on standardsmain), under job keyscan, withsecrets: inherit.actionlintis clean. This repo has noactions.lock, so there is no transitive-closure risk.Note for open PRs
#61 (another session's) cannot satisfy the floor until this lands. After merge it needs its checks re-run (or a rebase) so that it emits
scan / gitleaks.Role in the rollout
Positive-control pilot for D243. Measured: while only
scan / gitleakswas pending,mergeStateStatusread BLOCKED; once it went green, UNSTABLE. So the floor gates mergeability. This PR was not armed for auto-merge:scan / gitleakscompleted (~20–60 s) before arming could be issued, and arming an UNSTABLE PR merges it instantly. The landing form is pending an owner decision.Deferred checks
Hypatia(non-required) — WH008 note onsecrets: inherit: deferred to Hypatia workflow_hardening triage: secrets-inherit convention + WH013/WH006 false positives (7 instances) standards#943. The reusablesecret-scanner-reusable.ymlheader mandatessecrets: inheritfor callers; the convention is triaged there, not per-repo.🤖 Generated with Claude Code
https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK