Commit 7d024c1
fix(ci): drop the leftover trufflehog step — the estate retired it for gitleaks (#73)
`quality.yml` carries a **trufflehog** step that the estate already
decided against.
The standards secret-scanner reusable records the ruling in its own
header:
> *"Rationale for gitleaks over trufflehog: … Trufflehog was removed as
redundant; gitleaks catches what we need"*
> *"Trufflehog removed: gitleaks provides sufficient coverage at lower
cost."*
So this is **not a coverage trade-off**. It is a straggler from before
that decision — usually carrying `continue-on-error: true`, so it sits
inside a check it cannot fail, duplicating a scanner that was
deliberately dropped.
## Removing it loses nothing
This repo keeps gitleaks-backed scanning, and the sweep **re-verified
that from this checkout** before touching anything. Repos where
trufflehog is the *only* leak scanner were deliberately excluded — **33
of them estate-wide** — because they need gitleaks **added**, which is a
different change and must not be disguised as this one.
Gitleaks is also the stronger scan here: it runs over the whole working
tree with `--no-git` and exits non-zero on a finding, whereas this step
scanned `base..head`. **A diff is narrower than the tree.**
## Estate coverage, measured
Across 364 repositories with workflows (60 more have none at all):
| | count | |
|---|---:|---|
| gitleaks only | 170 (47%) | correct |
| trufflehog **and** gitleaks | 73 (20%) | this PR's category —
straggler removal |
| **trufflehog only** | **33 (9%)** | **must gain gitleaks first —
excluded here** |
| **neither** | **88 (24%)** | **no leak scanning at all** |
## A note on the lockfile edit
The `actions.lock` entry is removed by **indentation-aware traversal**,
not a line filter.
A line filter deletes the dependency key but leaves its four indented
children, which YAML then attaches to the **preceding** dependency. The
file still parses as valid YAML — the only symptom is every
lockfile-checked gate failing `startup_failure` with no explanation.
That happened once already in this campaign, on three repos at once, and
is why this sweep asserts every remaining dependency still carries its
own `commit` field before committing.
Found during the 2026-08-05 estate CI/CD census.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>1 parent 874140a commit 7d024c1
2 files changed
Lines changed: 0 additions & 14 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
40 | 40 | | |
41 | 41 | | |
42 | 42 | | |
43 | | - | |
44 | 43 | | |
45 | 44 | | |
46 | 45 | | |
| |||
138 | 137 | | |
139 | 138 | | |
140 | 139 | | |
141 | | - | |
142 | | - | |
143 | | - | |
144 | | - | |
145 | | - | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
30 | | - | |
31 | | - | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
37 | | - | |
38 | 30 | | |
39 | 31 | | |
40 | 32 | | |
| |||
0 commit comments