From 42fe974896de7e154af7bb7941c426fb54c14f11 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 21 Jul 2026 06:24:18 +0100 Subject: [PATCH] fix(ci): grant the secret-scanner reusable its required job permissions MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The scan job calls secret-scanner-reusable.yml, whose gitleaks job declares pull-requests: write (PR summary comment) and actions: read (workflow-run metadata) at job level. A called reusable workflow may only request permissions equal to or more restrictive than its caller, and this caller granted only the file-level contents: read — so GitHub refused the run at parse time. Every Secret Scanner run ended in startup_failure, meaning secret scanning has never actually executed in this repo. Grants the superset at job level, matching the canonical template and the 176 estate repos whose scanner already runs. No SHA pin is changed. Co-Authored-By: Claude Opus 4.8 --- .github/workflows/secret-scanner.yml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index d713d06..8308b58 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -15,5 +15,12 @@ permissions: jobs: scan: + # The reusable's gitleaks job requests pull-requests: write (PR summary + # comment) and actions: read (workflow-run metadata) at job level; the + # caller must grant at least that or the run startup-fails. + permissions: + contents: read + pull-requests: write + actions: read uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@d135b05bfc647d0c0fbfedc7e80f37ea50f49236 secrets: inherit