ci: add secret scanning on pull requests - #1
guiddeco-idans-claude[bot] wants to merge 1 commit into
Conversation
Completed Working on "Code Review "✅ Review comments published and final review submitted successfully. Event: COMMENT. Total comments: 1 across 1 files. ✅ Workflow completed successfully. |
There was a problem hiding this comment.
Review Summary
Findings by importance:
- MAJOR: 1
- BLOCKER/CRITICAL/MINOR/SUGGESTION/PRAISE: 0
Key themes observed:
- CI reliability gap in secret-scanning workflow — current concurrency settings can allow PR scans to be cancelled without a completed replacement result.
- Potential security visibility risk — in report-only mode, missed scan completion can mask findings prior to merge.
Actionable next steps:
- Update the workflow concurrency strategy to ensure deterministic scan coverage per PR commit (e.g., include PR number + SHA in group key), or enforce at least one successful scan completion for the latest commit via guard/retry logic.
- Re-run the workflow on the PR after adjustment to verify findings are consistently reported.
|
|
||
| permissions: {} | ||
|
|
||
| concurrency: |
There was a problem hiding this comment.
[major]: Using concurrency.group keyed only by github.ref with cancel-in-progress: true can cancel an older scan before it reports findings, while a newer run may fail or be cancelled too. In report-only mode (fail_on_findings: false), this can leave the PR without any secret-scan result and mask issues before merge.
|
Closing this — secret scanning is now enforced through an organization-level ruleset that applies to every repository, so a per-repo workflow is redundant. No action needed here; the branch has been deleted. |
Secret Scanning on Pull Requests
Adds
.github/workflows/secret-scanning.yaml, which calls the sharedguiddeco/shared-workflows/.github/workflows/ci-secret-scanning.yaml@v1reusable workflow on every PR targeting a long-lived branch.
fail_on_findings: false) — it comments findings onthe PR but does not block the merge.
permissions: {}with read-only job scope pluspull-requests: writefor the findings comment.
Part of an org-wide rollout — the same PR is open on every non-archived repo.