Skip to content

ci: add secret scanning on pull requests - #1

Closed
guiddeco-idans-claude[bot] wants to merge 1 commit into
developfrom
feature/adding_secret_scanning_on_pr
Closed

guiddeco-idans-claude[bot] wants to merge 1 commit into
developfrom
feature/adding_secret_scanning_on_pr

Conversation

@guiddeco-idans-claude

Copy link
Copy Markdown

Secret Scanning on Pull Requests

Adds .github/workflows/secret-scanning.yaml, which calls the shared
guiddeco/shared-workflows/.github/workflows/ci-secret-scanning.yaml@v1
reusable workflow on every PR targeting a long-lived branch.

  • Runs in report-only mode (fail_on_findings: false) — it comments findings on
    the PR but does not block the merge.
  • Top-level permissions: {} with read-only job scope plus pull-requests: write
    for the findings comment.

Part of an org-wide rollout — the same PR is open on every non-archived repo.

@overcut-ai

overcut-ai Bot commented Aug 11, 2026 •

Copy link
Copy Markdown

Completed Working on "Code Review "

✅ Review comments published and final review submitted successfully. Event: COMMENT. Total comments: 1 across 1 files.

✅ Workflow completed successfully.


👉 View complete log

@overcut-ai overcut-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review Summary

Findings by importance:

  • MAJOR: 1
  • BLOCKER/CRITICAL/MINOR/SUGGESTION/PRAISE: 0

Key themes observed:

  1. CI reliability gap in secret-scanning workflow — current concurrency settings can allow PR scans to be cancelled without a completed replacement result.
  2. Potential security visibility risk — in report-only mode, missed scan completion can mask findings prior to merge.

Actionable next steps:

  • Update the workflow concurrency strategy to ensure deterministic scan coverage per PR commit (e.g., include PR number + SHA in group key), or enforce at least one successful scan completion for the latest commit via guard/retry logic.
  • Re-run the workflow on the PR after adjustment to verify findings are consistently reported.


permissions: {}

concurrency:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[major]: Using concurrency.group keyed only by github.ref with cancel-in-progress: true can cancel an older scan before it reports findings, while a newer run may fail or be cancelled too. In report-only mode (fail_on_findings: false), this can leave the PR without any secret-scan result and mask issues before merge.

@guiddeco-idans-claude

Copy link
Copy Markdown
Author

Closing this — secret scanning is now enforced through an organization-level ruleset that applies to every repository, so a per-repo workflow is redundant. No action needed here; the branch has been deleted.

@guiddeco-idans-claude
guiddeco-idans-claude Bot deleted the feature/adding_secret_scanning_on_pr branch August 11, 2026 14:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants