Skip to content

Commit f3b25b6

Browse files
hyperpolymathclaude
andcommitted
fix(ci): grant the secret-scanner reusable its required job permissions
The scan job calls secret-scanner-reusable.yml, whose gitleaks job declares pull-requests: write (PR summary comment) and actions: read (workflow-run metadata) at job level. A called reusable workflow may only request permissions equal to or more restrictive than its caller, and this caller granted only the file-level contents: read — so GitHub refused the run at parse time. Every Secret Scanner run ended in startup_failure, meaning secret scanning has never actually executed in this repo. Grants the superset at job level, matching the canonical template and the 176 estate repos whose scanner already runs. No SHA pin is changed. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1 parent ff12430 commit f3b25b6

1 file changed

Lines changed: 7 additions & 0 deletions

File tree

.github/workflows/secret-scanner.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,5 +12,12 @@ permissions:
1212
contents: read
1313
jobs:
1414
scan:
15+
# The reusable's gitleaks job requests pull-requests: write (PR summary
16+
# comment) and actions: read (workflow-run metadata) at job level; the
17+
# caller must grant at least that or the run startup-fails.
18+
permissions:
19+
contents: read
20+
pull-requests: write
21+
actions: read
1522
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@d135b05bfc647d0c0fbfedc7e80f37ea50f49236
1623
secrets: inherit

0 commit comments

Comments
 (0)