Skip to content

Commit 92bf3ad

Browse files
fix(ci): grant the secret-scanner reusable its required job permissions (#25)
Supersedes #24 (that branch's commit was unsigned and blocked by the required-signatures rule). Every `Secret Scanner` run in this repo ended in **`startup_failure`** — secret scanning never actually executed. **Root cause:** a called reusable workflow may only request permissions equal to or more restrictive than its caller, enforced at parse time. `secret-scanner-reusable.yml`'s `gitleaks` job declares `pull-requests: write` + `actions: read`; this caller granted only `contents: read`, so the run was refused before a runner was allocated. **Fix:** grant the superset at job level, byte-identical to the canonical template. No SHA pin changed. **Verified:** on the equivalent branch, Secret Scanner went `startup_failure` → `success` with `gitleaks`, `rust-secrets`, `shell-secrets` all passing. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
1 parent 38991c3 commit 92bf3ad

1 file changed

Lines changed: 7 additions & 0 deletions

File tree

.github/workflows/secret-scanner.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,5 +15,12 @@ permissions:
1515

1616
jobs:
1717
scan:
18+
# The reusable's gitleaks job requests pull-requests: write (PR summary
19+
# comment) and actions: read (workflow-run metadata) at job level; the
20+
# caller must grant at least that or the run startup-fails.
21+
permissions:
22+
contents: read
23+
pull-requests: write
24+
actions: read
1825
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@c65436ee3351cd6b0fa14b142938b195efc77586
1926
secrets: inherit

0 commit comments

Comments
 (0)