Skip to content

chore(ci): replace secret-scanner.yml with reusable wrapper#17

Open
hyperpolymath wants to merge 1 commit into
mainfrom
chore/secret-scanner-reusable-wrapper
Open

chore(ci): replace secret-scanner.yml with reusable wrapper#17
hyperpolymath wants to merge 1 commit into
mainfrom
chore/secret-scanner-reusable-wrapper

Conversation

@hyperpolymath
Copy link
Copy Markdown
Owner

Summary

Replaces this repo's secret-scanner.yml (~75-116 lines) with a thin ~14-line wrapper calling hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@3e4bd4c93911750727e2e4c66dff859e00079da0 (merged via standards#190).

Security debt closed

The shell-secrets job (added post-Cloudflare-leak 2026-05-21 in response to the live API-token leak via avow-protocol/deploy-repos.sh) was carried by 0 of 16 sampled estate copies. This PR brings the guardrail to this repo.

Why now

Estate audit: 281 deployments / 54 unique SHAs / 19% true drift. Drift is pin churn + whitespace, feature variance near-zero. Converging behind the reusable means the next post-incident guardrail update propagates via one SHA bump.

secrets: inherit flows GITHUB_TOKEN through implicitly so gitleaks-action doesn't fall back to anonymous (rate-limited) mode.

Part of estate-wide convergence campaign 2026-05-26 (standards#199 / #190).

Pins to hyperpolymath/standards#190 merge SHA 3e4bd4c93911750727e2e4c66dff859e00079da0. Force-propagates
the shell-secrets job (added post-Cloudflare-leak 2026-05-21) to this
repo's secret-scanning gate. Replaces ~75-116 lines with a ~14-line wrapper.

Part of estate-wide convergence campaign 2026-05-26
(standards#199 / #190).
@hyperpolymath hyperpolymath enabled auto-merge (squash) May 26, 2026 16:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant