Skip to content

Commit 446ac06

Browse files
hyperpolymathclaude
andcommitted
fix(ci): grant the secret-scanner reusable its required job permissions
The scan job calls secret-scanner-reusable.yml, whose gitleaks job declares pull-requests: write (PR summary comment) and actions: read (workflow-run metadata) at job level. A called reusable workflow may only request permissions equal to or more restrictive than its caller, and this caller granted only the file-level contents: read — so GitHub refused the run at parse time. Every Secret Scanner run ended in startup_failure, meaning secret scanning has never actually executed in this repo. Grants the superset at job level, matching the canonical template and the 176 estate repos whose scanner already runs. No SHA pin is changed. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1 parent 6167269 commit 446ac06

1 file changed

Lines changed: 7 additions & 0 deletions

File tree

.github/workflows/secret-scanner.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,5 +15,12 @@ permissions:
1515

1616
jobs:
1717
scan:
18+
# The reusable's gitleaks job requests pull-requests: write (PR summary
19+
# comment) and actions: read (workflow-run metadata) at job level; the
20+
# caller must grant at least that or the run startup-fails.
21+
permissions:
22+
contents: read
23+
pull-requests: write
24+
actions: read
1825
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@d135b05bfc647d0c0fbfedc7e80f37ea50f49236
1926
secrets: inherit

0 commit comments

Comments
 (0)