Skip to content

ci(secret-scan): rename caller job key secret-scan -> scan (D243) - #50

Merged
hyperpolymath merged 1 commit into
mainfrom
ci/secret-scan-floor-key
Oct 1, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
ci/secret-scan-floor-key

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

What

Rename the secret-scanner caller job key secret-scan → scan in .github/workflows/secret-scanner.yml, so the check context becomes scan / gitleaks — the context the estate Secret-Scan-Floor ruleset (D243/D244) requires. One-line change; reusable pin, triggers and permissions unchanged. actionlint output is identical before and after.

Commit created via GraphQL createCommitOnBranch (GitHub-signed, signature valid: true).

🤖 Generated with Claude Code

https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK

Secret-Scan-Floor (D243/D244) requires the context `scan / gitleaks` estate-wide. The caller job key here was `secret-scan`, which emits `secret-scan / gitleaks` and can never satisfy the floor. Rename only; the reusable pin and permissions are unchanged.

actionlint output identical before and after.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 69bcff13-84a5-406f-affb-9c37f93ab4c7

📥 Commits

Reviewing files that changed from the base of the PR and between 6dde9fb and e8a5d6d.

📒 Files selected for processing (1)
  • .github/workflows/secret-scanner.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (4)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (actions)
  • GitHub Check: Analyze (rust)
  • GitHub Check: Analyze (ruby)
⚠️ CI failures not shown inline (8)

GitHub Actions: Anchor Drift / 0_membership-integrity.txt: ci(secret-scan): rename caller job key secret-scan -> scan (D243)

Conclusion: failure

View job details

##[group]Run scripts/check-membership.sh
 �[36;1mscripts/check-membership.sh�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 membership error: .gitmodules members/implementations/k9-rs url is '', expected 'https://github.com/hyperpolymath/k9-rs.git'
 membership error: .gitmodules members/implementations/k9-rs branch is '', expected 'main'
 membership error: members/implementations/k9-rs is not a pinned submodule gitlink
 membership error: .gitmodules members/implementations/k9_ex url is '', expected 'https://github.com/hyperpolymath/k9_ex.git'
 membership error: .gitmodules members/implementations/k9_ex branch is '', expected 'main'
 membership error: members/implementations/k9_ex is not a pinned submodule gitlink
 membership error: .gitmodules members/implementations/k9_gleam url is '', expected 'https://github.com/hyperpolymath/k9_gleam.git'
 membership error: .gitmodules members/implementations/k9_gleam branch is '', expected 'main'
 membership error: members/implementations/k9_gleam is not a pinned submodule gitlink
 membership error: .gitmodules members/implementations/k9-deno url is '', expected 'https://github.com/hyperpolymath/k9-deno.git'
 membership error: .gitmodules members/implementations/k9-deno branch is '', expected 'main'
 membership error: members/implementations/k9-deno is not a pinned submodule gitlink
 membership error: .gitmodules members/implementations/k9-haskell url is '', expected 'https://github.com/hyperpolymath/k9-haskell.git'
 membership error: .gitmodules members/implementations/k9-haskell branch is '', expected 'main'
 membership error: members/implementations/k9-haskell is not a pinned submodule gitlink
 membership error: .gitmodules members/tooling/tree-sitter-k9 url is '', expected 'https://github.com/hyperpolymath/tree-sitter-k9.git'
 membership error: .gitmodules members/tooling/tree-sitter-k9 branch is '', expected 'main'
 membership error: members/tooling/tree-sitter-k9 is not a pinned submodule gitlink
 membership error: .g...

GitHub Actions: Anchor Drift / membership-integrity: ci(secret-scan): rename caller job key secret-scan -> scan (D243)

Conclusion: failure

View job details

##[group]Run scripts/check-membership.sh
 �[36;1mscripts/check-membership.sh�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 membership error: .gitmodules members/implementations/k9-rs url is '', expected 'https://github.com/hyperpolymath/k9-rs.git'
 membership error: .gitmodules members/implementations/k9-rs branch is '', expected 'main'
 membership error: members/implementations/k9-rs is not a pinned submodule gitlink
 membership error: .gitmodules members/implementations/k9_ex url is '', expected 'https://github.com/hyperpolymath/k9_ex.git'
 membership error: .gitmodules members/implementations/k9_ex branch is '', expected 'main'
 membership error: members/implementations/k9_ex is not a pinned submodule gitlink
 membership error: .gitmodules members/implementations/k9_gleam url is '', expected 'https://github.com/hyperpolymath/k9_gleam.git'
 membership error: .gitmodules members/implementations/k9_gleam branch is '', expected 'main'
 membership error: members/implementations/k9_gleam is not a pinned submodule gitlink
 membership error: .gitmodules members/implementations/k9-deno url is '', expected 'https://github.com/hyperpolymath/k9-deno.git'
 membership error: .gitmodules members/implementations/k9-deno branch is '', expected 'main'
 membership error: members/implementations/k9-deno is not a pinned submodule gitlink
 membership error: .gitmodules members/implementations/k9-haskell url is '', expected 'https://github.com/hyperpolymath/k9-haskell.git'
 membership error: .gitmodules members/implementations/k9-haskell branch is '', expected 'main'
 membership error: members/implementations/k9-haskell is not a pinned submodule gitlink
 membership error: .gitmodules members/tooling/tree-sitter-k9 url is '', expected 'https://github.com/hyperpolymath/tree-sitter-k9.git'
 membership error: .gitmodules members/tooling/tree-sitter-k9 branch is '', expected 'main'
 membership error: members/tooling/tree-sitter-k9 is not a pinned submodule gitlink
 membership error: .g...

GitHub Actions: Anchor Drift / membership-integrity: ci(secret-scan): rename caller job key secret-scan -> scan (D243)

Conclusion: failure

View job details

Post job cleanup.
 [command]/usr/bin/git version
 git version 2.55.0
 Temporarily overriding HOME='/home/runner/work/_temp/3b3715bc-4ae3-4ab0-8f05-b7a8fc0f2654' before making global git config changes
 Adding repository directory to the temporary git global config as a safe directory
 [command]/usr/bin/git config --global --add safe.directory /home/runner/work/k9-ecosystem/k9-ecosystem
 [command]/usr/bin/git config --local --name-only --get-regexp core\.sshCommand
 [command]/usr/bin/git submodule foreach --recursive sh -c "git config --local --name-only --get-regexp 'core\.sshCommand' && git config --local --unset-all 'core.sshCommand' || :"
 fatal: No url found for submodule path 'members/ci/k9-pre-commit' in .gitmodules
 ##[warning]The process '/usr/bin/git' failed with exit code 128

GitHub Actions: Anchor Drift / 1_upstream-pins.txt: ci(secret-scan): rename caller job key secret-scan -> scan (D243)

Conclusion: failure

View job details

Current runner version: '2.337.0'
 ##[group]Runner Image Provisioner
 Hosted Compute Agent
 Version: 20260901.588
 Commit: f88ec8081b781fac6c440065ac7ff9e710ce3d0b
 Build Date:
 Worker ID: {0b008dd3-d6b5-4f6e-b2a8-56253078a2bb}
 Azure Region: westus3
 ##[endgroup]
 ##[group]Operating System
 Ubuntu
 24.04.5
 LTS
 ##[endgroup]
 ##[group]Runner Image
 Image: ubuntu-24.04
 Version: 20260927.320.1
 Included Software: https://github.com/actions/runner-images/blob/ubuntu24/20260927.320/images/ubuntu/Ubuntu2404-Readme.md
 Image Release: https://github.com/actions/runner-images/releases/tag/ubuntu24%2F20260927.320
 ##[endgroup]
 ##[group]GITHUB_TOKEN Permissions
 Contents: read
 Metadata: read
 ##[endgroup]
 Secret source: Actions
 Cache mode: write
 Prepare workflow directory
 Prepare all required actions
 Getting action download info
 Download action repository 'actions/checkout@11d5960a326750d5838078e36cf38b85af677262' (SHA:11d5960a326750d5838078e36cf38b85af677262)
 Complete job name: upstream-pins
 ##[group]Run actions/checkout@11d5960a326750d5838078e36cf38b85af677262
 with:
   repository: hyperpolymath/k9-ecosystem
   ***REDACTED_SECRET_ASSIGNMENT***
   ssh-strict: true
   ssh-user: git
   persist-credentials: true
   clean: true
   sparse-checkout-cone-mode: true
   fetch-depth: 1
   fetch-tags: false
   show-progress: true
   lfs: false
   submodules: false
   set-safe-directory: true
   allow-unsafe-pr-checkout: false
 ##[endgroup]
 Syncing repository: hyperpolymath/k9-ecosystem
 ##[group]Getting Git version info
 Working directory is '/home/runner/work/k9-ecosystem/k9-ecosystem'
 [command]/usr/bin/git version
 git version 2.55.0
 ##[endgroup]
 Temporarily overriding HOME='/home/runner/work/_temp/374918cb-b9ca-4e97-9c90-2680481a4f9f' before making global git config changes
 Adding repository directory to the temporary git global config as a safe directory
 [command]/usr/bin/git config --global --add safe.directory /home/runner/work/k9-ecosystem/k9-ecosystem
 Dele...

GitHub Actions: Anchor Drift / upstream-pins: ci(secret-scan): rename caller job key secret-scan -> scan (D243)

Conclusion: failure

View job details

Post job cleanup.
 [command]/usr/bin/git version
 git version 2.55.0
 Temporarily overriding HOME='/home/runner/work/_temp/7216a776-8b43-42b6-8d22-9acfdfb661dc' before making global git config changes
 Adding repository directory to the temporary git global config as a safe directory
 [command]/usr/bin/git config --global --add safe.directory /home/runner/work/k9-ecosystem/k9-ecosystem
 [command]/usr/bin/git config --local --name-only --get-regexp core\.sshCommand
 [command]/usr/bin/git submodule foreach --recursive sh -c "git config --local --name-only --get-regexp 'core\.sshCommand' && git config --local --unset-all 'core.sshCommand' || :"
 fatal: No url found for submodule path 'members/ci/k9-pre-commit' in .gitmodules
 ##[warning]The process '/usr/bin/git' failed with exit code 128

GitHub Actions: Anchor Drift / 2_governance-validation.txt: ci(secret-scan): rename caller job key secret-scan -> scan (D243)

Conclusion: failure

View job details

##[group]A2ML Manifest Validation
 Scanning . for .a2ml files...
 ##[notice]Skipped 1 file(s) matching paths-ignore
 Found 754 .a2ml file(s)
   Validating: ./.machine_readable/anchors/ANCHOR.a2ml
   Validating: ./.machine_readable/descriptiles/AGENTIC.a2ml
   Validating: ./.machine_readable/descriptiles/ECOSYSTEM.a2ml
   Validating: ./.machine_readable/descriptiles/META.a2ml
   Validating: ./.machine_readable/descriptiles/NEUROSYM.a2ml
   Validating: ./.machine_readable/descriptiles/PLAYBOOK.a2ml
   Validating: ./.machine_readable/descriptiles/STATE.a2ml
   Validating: ./0-AI-MANIFEST.a2ml
   Validating: ./deno/.github/0.1-AI-MANIFEST.a2ml
 ##[error]Missing SPDX-License-Identifier in first 10 lines

GitHub Actions: Anchor Drift / governance-validation: ci(secret-scan): rename caller job key secret-scan -> scan (D243)

Conclusion: failure

View job details

##[group]A2ML Manifest Validation
 Scanning . for .a2ml files...
 ##[notice]Skipped 1 file(s) matching paths-ignore
 Found 754 .a2ml file(s)
   Validating: ./.machine_readable/anchors/ANCHOR.a2ml
   Validating: ./.machine_readable/descriptiles/AGENTIC.a2ml
   Validating: ./.machine_readable/descriptiles/ECOSYSTEM.a2ml
   Validating: ./.machine_readable/descriptiles/META.a2ml
   Validating: ./.machine_readable/descriptiles/NEUROSYM.a2ml
   Validating: ./.machine_readable/descriptiles/PLAYBOOK.a2ml
   Validating: ./.machine_readable/descriptiles/STATE.a2ml
   Validating: ./0-AI-MANIFEST.a2ml
   Validating: ./deno/.github/0.1-AI-MANIFEST.a2ml
 ##[error]Missing SPDX-License-Identifier in first 10 lines

GitHub Actions: Anchor Drift / governance-validation: ci(secret-scan): rename caller job key secret-scan -> scan (D243)

Conclusion: failure

View job details

Post job cleanup.
 [command]/usr/bin/git version
 git version 2.55.0
 Temporarily overriding HOME='/home/runner/work/_temp/6da2124b-3653-47e9-bbda-af410c06bd33' before making global git config changes
 Adding repository directory to the temporary git global config as a safe directory
 [command]/usr/bin/git config --global --add safe.directory /home/runner/work/k9-ecosystem/k9-ecosystem
 [command]/usr/bin/git config --local --name-only --get-regexp core\.sshCommand
 [command]/usr/bin/git submodule foreach --recursive sh -c "git config --local --name-only --get-regexp 'core\.sshCommand' && git config --local --unset-all 'core.sshCommand' || :"
 fatal: No url found for submodule path 'members/ci/k9-pre-commit' in .gitmodules
 ##[warning]The process '/usr/bin/git' failed with exit code 128
🔇 Additional comments (1)
.github/workflows/secret-scanner.yml (1)

18-18: LGTM!


📝 Summary

Summary by CodeRabbit

  • Chores
    • Updated the label used for an automated security scan. The scan continues to use the same process and access settings, so its behaviour is unchanged. There are no changes to application features or functionality in this update.

Walkthrough

The secret scanner workflow job key changes from secret-scan to scan. The reusable workflow and secret inheritance remain unchanged.

Changes

Secret scanner workflow

Layer / File(s) Summary
Rename workflow job key
.github/workflows/secret-scanner.yml
The job key changes from secret-scan to scan. The reusable workflow and secret inheritance remain unchanged.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to e8a5d

The workflow rename is limited and preserves its existing execution contract.

Architecture Summary

Architecture risk: 🔵 Low · up to e8a5d

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/secret-scanner.yml: The workflow job key changed from secret-scan to scan; its reusable workflow and secret inheritance remain unchanged.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely states the main change: renaming the secret-scanner caller job key from secret-scan to scan.
Description check ✅ Passed The description directly explains the job-key rename, the required check context, and the unchanged workflow settings. It is related to the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the scanner’s name,
The workflow keeps its call the same.
Secrets still pass along their way,
While scan now marks the job today.
The rabbit hops, then leaves the frame.

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit b129a7d into main Oct 1, 2026
13 of 15 checks passed
@hyperpolymath
hyperpolymath deleted the ci/secret-scan-floor-key branch October 1, 2026 12:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant