Skip to content

Secret-Scan-Floor (D243/D244): sweep results and open items with acceptance criteria #1108

Description

@hyperpolymath

Context

D243/D244 (owner ruling 2026-10-01) put an estate-wide Secret-Scan-Floor ruleset on every non-vault, non-fork repo whose default head emits scan / gitleaks: 336 repos (first pass: 312 created and 2 already present; second pass: 21 created and 1 already present). The 103 repos that do not yet emit the context have no floor, because a floor there would block every PR. Section 2, section 3 and the B-shape rename backlog cover them. The ruleset requires the context scan / gitleaks (integration 15368, admin-role bypass, target ~DEFAULT_BRANCH). The callers were made to emit that context by renaming the job key secret-scan → scan and by writing the canonical caller (secret-scanner-reusable.yml@74d2f66).

What landed and what is still open is recorded below. Each item that the sweep could not close is listed with acceptance criteria. Per the 09-15 standing ruling, a scanner finding is an issue, not a blocker.

Horizon: every measurement below is from the GraphQL API on 2026-10-01 between 12:00Z and 13:45Z, over the 439 repos of hyperpolymath + metadatastician that are not archived. The 3 gcrypt vaults and 5 forks were excluded by name.

1. Default branches RED at gitleaks — 31 repos (possible committed secrets)

Re-measured at each default-branch head (not the census snapshot). The gating gitleaks pass in secret-scanner-reusable.yml@74d2f66 scans the full history (fetch-depth: 0, it refuses a shallow clone, and its own comment says "The gate is full-history"). So on these repos every PR is red at scan / gitleaks too. 21 of them now carry the floor, which the owner accepted: their PRs are blocked until the finding is triaged, or merged by an admin bypass. The repos:

  • hyperpolymath/boj-server @ 0ba6a6c4

  • hyperpolymath/panic-attack @ 5ee25658

  • hyperpolymath/poly-observability-mcp @ 6fa74f22

  • hyperpolymath/panll @ 03583e9a

  • hyperpolymath/nickel-augmentation @ 77e39f76

  • hyperpolymath/lcb-website @ 345431e8

  • hyperpolymath/januskey @ fd0c56f9

  • hyperpolymath/hyperpolymath-sovereign-registry @ 89847c6a

  • hyperpolymath/hpm-crypto-rsr @ f1e42c97

  • hyperpolymath/frayed-knot-toolkit @ 07798e2a

  • hyperpolymath/laminar @ 582aa532

  • hyperpolymath/email-octad-experiment @ 5cd67a27

  • hyperpolymath/lithoglyph @ ba7ebe20

  • hyperpolymath/boj-server-cartridges @ 50b1af4c

  • hyperpolymath/contractiles-a2-lab @ 5943ae6b

  • hyperpolymath/blog-drafts @ 8c545cb2

  • hyperpolymath/007-lang @ 61054841

  • hyperpolymath/ipv6-tools @ 632bb26b

  • hyperpolymath/jtv-halting-islands-ct @ b41e29d1

  • hyperpolymath/zotero-tools @ 0a00bcfb

  • hyperpolymath/claude-memory @ 1299ac9b

  • hyperpolymath/typefix-zero @ ae598741

  • hyperpolymath/echobox @ bf6371bc

  • hyperpolymath/veridical-simulation-core @ 7b8297b3

  • hyperpolymath/jewell.nexus @ 48e66fdb

  • hyperpolymath/axel-protocol @ 9d077309

  • hyperpolymath/jonathanjewell.dev @ 56528d60

  • hyperpolymath/hpm-github-api-rsr @ 8274b3d5

  • metadatastician/insolvency-tycoon @ 4c52759a

  • metadatastician/enaction-engine @ 9165cf5d

  • metadatastician/burble @ b36f142a

  • Each repo: triage the gitleaks finding(s) on main. Either rotate and purge the secret, or add a reviewed .gitleaksignore entry naming the fingerprint and the reason.

  • scan / gitleaks (or secret-scan / gitleaks) is SUCCESS on the default-branch head.

2. Repos with actions.lock — caller not yet written (21)

The canonical caller calls hyperpolymath/standards@74d2f66…, whose job uses actions/checkout@3d3c42e5…. A lock that lacks either record startup-kills the caller. Repos: hyperpolymath/cicd-suite, hyperpolymath/marches, hyperpolymath/network-outpost, hyperpolymath/residual-evidence-types, hyperpolymath/smtp-notify-action, hyperpolymath/trigger, hyperpolymath/claude-integrations, hyperpolymath/flat-mate, hyperpolymath/kitchenspeak, hyperpolymath/knot-rider, metadatastician/common-signal, hyperpolymath/academic-workflow-suite, hyperpolymath/affinescript-vite, hyperpolymath/aspasia, hyperpolymath/bitfuckit, hyperpolymath/branch-newspaper, hyperpolymath/civic-connect, hyperpolymath/defiant, hyperpolymath/ideas-to-alphas, hyperpolymath/poly-k8s-mcp, metadatastician/proglanging-languages. proglanging-languages has an open PR (#3, the old pin @bd0df9ea with a lock missing a checkout record, so it startup-fails), which will be reworked under this item.

  • gh actions-lock gains callee-aware generation: locking a workflow that calls a reusable also records the reusable's own uses: (transitively closed).
  • Each listed repo gets the canonical caller plus lock records, verified with gh actions-lock --no-fix (not a hand-rolled check) before the PR opens.
  • The flat-mate class (callers at @84355587 with an extra inline trufflehog job and a lock missing actions/checkout@3d3c42e5) is covered by the same fix.

3. Private repos — Actions availability unproven (6)

hyperpolymath/lfs-shared, hyperpolymath/linguist, hyperpolymath/multiterm, metadatastician/bowtie-workbench, metadatastician/reflexive-ai-studio, hyperpolymath/polystack — no caller was written. If Actions cannot run (billing), a floor deadlocks every PR.

  • Each: establish whether Actions run (a workflow run on the default head in the last 30 days), then either write the caller or record an exemption.

4. Phantom and dead reusable pins

  • metadatastician/common-signal: secret-scanner.yml pins @5b1d0022, which does not exist in hyperpolymath/standards ("failed to fetch workflow"). Its lock entry for the file is [].
  • Pins @892497fe and @7fdc2705 fail with "error parsing called workflow … workflow was not found".
  • A lock/pin validator rejects a reusable SHA that does not resolve in the callee repo (shape-checked: 40 hex characters and the object exists).

5. Rulesets that already require the OLD context — irreversible-cutover shape

epistemic-types (secret-scan / gitleaks), deed-ecosystem (secret-scan / gitleaks, rust-secrets, shell-secrets), firmboot (firmboot-continuity-proof-branch requires secret-scan / gitleaks). Renaming the key here deadlocks every PR until the ruleset changes.

  • Owner decision per repo. The shim is: open the rename PR, updateRepositoryRuleset swapping the contexts to scan / …, then merge.

6. Invalid caller files (never ran)

6a. Startup failures unrelated to the caller (17 INSPECT rows)

  • "Actor is not allowed to trigger Actions workflows": aerie, docudactyl, iseriser, occupancy-types, proven. Every head suite startup-fails, so no scanner context ever lands.
  • "Invalid lockfile": awesome-idris2, cafescripto, eclexia, lucidscript, social-media-tools, universal-chat-extractor. The lock must be repaired before the caller can be bumped or replaced.
  • No scanner suite on head after a dependabot bump: dictask, first-post.
  • the-nash-equilibrium (guard-defective, do not merge) and affinescript (a deliberately inline scan job that emits a bare scan) were left alone on purpose.
  • Each: the cause is identified, and scan / gitleaks reports on the default head.

6b. The reusable's header still says secrets: inherit is REQUIRED — false at @74d2f66

.github/workflows/secret-scanner-reusable.yml lines 32-35 tell callers to pass secrets: inherit, or else "the gitleaks action's inner secrets.GITHUB_TOKEN is empty". At 74d2f66 the reusable has no ${{ secrets.* }} reference, and gitleaks runs as a checksum-verified binary (line 45 says it replaced gitleaks/gitleaks-action). So secrets: inherit only forwards every repo and org secret to it (CWE-250). CodeRabbit (oikosbot-estate#3) and Hypatia WH008 (launch-scaffolder#68) both flagged it.

This sweep's caller template copied the false note. It was corrected in all 26 caller PRs and in zerostep#102, each by a second signed commit. Positive control: zerostep#102 went green on all three scan / jobs with no secrets passed.

  • The reusable's header drops the secrets: inherit instruction and says the caller needs no secrets: line.
  • Existing callers that still pass secrets: inherit to this reusable are listed and dropped (a census keyed on content).

6c. New caller PRs RED at gitleaks (4)

These PRs only add or replace the caller file. Their scan / gitleaks is FAILURE on the PR head. The gating pass scans the full history, so the finding is almost certainly pre-existing history these repos had never scanned, not the PR diff (triage pending): hyperpolymath/ambientops#381, hyperpolymath/palimpsest-license#161, metadatastician/project-ovine#34, hyperpolymath/misinformation-defence-platform#85. Each repo's default branch had no running scanner before (ADD/BUMP/REPLACE), so this is likely the first scan these repos have had.

  • Each: the finding is triaged (rotate and purge, or a reviewed .gitleaksignore entry), and the PR goes green and lands.

6d. Caller PRs BLOCKED by non-check rules (7)

All 7 have scan / gitleaks = SUCCESS. Each is blocked by another rule type:

  • oikosbot-estate#3: CodeRabbit CHANGES_REQUESTED. The thread (remove secrets: inherit) was fixed and resolved, and the review now needs re-evaluation or dismissal.
  • ci(secret-scan): canonical estate scanner caller, key scan (D243) metadatastician/authority-watch#5: code-owner review, CODE_SCANNING, and COPILOT_CODE_REVIEW (EstateBranching).
  • JuliaPackage-Reuse-Audit.jl#66, live-files#61, MacroPower.jl#30, megadog#74, neural-foundations#99: blocked by a non-check rule.
  • Each: the blocking rule type is named from rules/branches/{base}, then satisfied or waived by the owner.

7. Default branch ≠ trigger branch

HOL (default develop, trigger [main, master]) and rescript (default ci/burn-reduction-triggers-concurrency). No scanner context ever lands on the default branch.

  • The canonical caller's push trigger names the repo's actual default branch; a census flags mismatches.

8. Tooling/process defects found during the sweep

  • apps-ack-gate fails OPEN under the REST secondary limit. During a REST secondary 403 (core rate_limit reading 5000 remaining, 0 used), the enumerator returned {"error":"cannot read … pulls/N"} with rc=0. The hook's bail() then allowed the merge on its first call, with no ack table. 8 merges ran without App enumeration: hyperpolymath/bebop-ffi#82, hyperpolymath/awesome-agda#8, hyperpolymath/info#15, hyperpolymath/trope-checker#96, hyperpolymath/trope-particularity-workbench#73, hyperpolymath/awesome-haskell#14, hyperpolymath/ai-cli-lab#12, hyperpolymath/cut-calculus#12. All 8 landed GitHub-signed; post-hoc enumeration: pending: the REST secondary limit was still active at 13:18Z. Results will be posted as a comment on this issue..
    • The hook fails CLOSED (deny, with a visible reason) when it cannot enumerate. A deny is recoverable; a silent pass is not.
    • The enumerator exits non-zero on an error body (shape-check the response, not just rc).
  • rate_limit cannot see the secondary limit. Any pacing that reads core.remaining will keep hammering.
    • Pacing keys on the 403 body / retry-after, not on rate_limit.
  • Census NOFILE label keyed on filename mislabelled flat-mate (secret-scan.yml) and firmboot (secrets.yml) as having no caller.
    • The census keys on content (secret-scanner-reusable.yml@), not on the filename.
  • Automerge does not re-fire after a ruleset-only change. A PR whose blocking rule is removed stays armed and unmerged until a new event.
    • Documented; sweeps re-evaluate armed PRs after a ruleset edit.

Landed in this sweep

🤖 Generated with Claude Code

https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK

Activity

  1. hyperpolymath commented on Oct 1, 2026

    @hyperpolymath
    OwnerAuthor

    D243 phase 2 — landing update (2026-10-01)

    Landed: 77 caller PRs. All were squash-merged and all merge commits are GitHub-signed (signature.isValid=true). That is 44 earlier and 33 in this batch.

    Each was merged by a literal per-PR squash command, one PR per command, and only once it was CLEAN or UNSTABLE with scan / gitleaks = SUCCESS. None was merged while BLOCKED, and --admin was never used.

    This batch (33): PR → merge commit

    Red checks deferred under §5c item 3 (5 PRs)

    Each PR below changes only .github/workflows/secret-scanner.yml. The red checks on it belong to the repository, not to that change:

    Red check Cause
    Actions lockfile The grace window closed on 2026-10-01, so the check now fails
    Guix policy "No packaging found"
    Workflow security linter A scorecard.yml pin to standards@892497fe that predates the PR and is not an ancestor of main
    ClusterFuzzLite No Dockerfile

    Each PR has an issue with acceptance criteria, and the PR body names each red context and links that issue:

    Post-hoc App enumeration (apps-ack-gate failed open)

    While the REST secondary limit is in force, apps-ack-gate fails open: it allows the merge with the message "Apps are NOT being enumerated". That is a defect in the gate in its own right. The enumerations below were run after the merges to cover the gap.

    Wave 1 (8 PRs, 12:4xZ window):

    • All 8 enumerated with err=none.
    • required_failing and required_absent are empty on every one.
    • A non-required github-actions FAILURE appears on 7 of them.
    • The legacy hyperpolymath status is PENDING on ai-cli-lab#12 and cut-calculus#12.
    • These surface but do not block.

    Wave 2 (16 PRs, 14:06–14:16Z window; enumerated after the limit cleared at 14:31Z):

    • All 16 enumerated with err=none, and required_failing and required_absent are empty on every one.
    • ⚠ That result is vacuous. All 16 repos had required: [] when they merged: they had no Secret-Scan-Floor yet, because they had no caller. An empty required_absent over an empty required set proves nothing. (Wave 1's 8 do carry required: ["scan / gitleaks"], so their result is real.)
    • A non-required github-actions FAILURE appears on jaffascript#65, LowLevel.jl#31 and phantom-metal-taste#76, plus the 5 deferred above. hyperpolymath status is PENDING on launch-scaffolder#68 and LowLevel.jl#31.

    Floors now applied to all 33 repos in this batch.

    • Before creating each floor, I read scan / gitleaks on the default-branch head. It was SUCCESS on all 33, so no floor creates a deadlock.
    • createRepositoryRuleset returned CREATED 33/33.
    • rules/branches/<default> now returns required_status_checks = scan / gitleaks on 33/33.

    §5c deferrals for the remaining reds (10 PRs). Each issue lists every red context on the PR head, gives a diagnosed cause where one was read, and states acceptance criteria. Each PR body links its issue:

    PR Issue Reds
    hyperpolymath/jaffascript#65 hyperpolymath/jaffascript#66 1
    hyperpolymath/LowLevel.jl#31 hyperpolymath/LowLevel.jl#32 4
    hyperpolymath/phantom-metal-taste#76 hyperpolymath/phantom-metal-taste#77 2
    hyperpolymath/bebop-ffi#82 hyperpolymath/bebop-ffi#83 2
    hyperpolymath/info#15 hyperpolymath/info#16 4
    hyperpolymath/trope-checker#96 hyperpolymath/trope-checker#97 9
    hyperpolymath/trope-particularity-workbench#73 hyperpolymath/trope-particularity-workbench#74 5
    hyperpolymath/awesome-haskell#14 hyperpolymath/awesome-haskell#15 2
    hyperpolymath/ai-cli-lab#12 hyperpolymath/ai-cli-lab#13 2
    hyperpolymath/cut-calculus#12 hyperpolymath/cut-calculus#13 2

    Two estate-wide causes were found along the way. Each needs its own standards fix:

    1. Workflow security lint (lint-workflows) flags every workflow in a repo that gh actions-lock manages. The linter requires # SPDX-License-Identifier: on line 1, but actions-lock writes # This workflow is managed by gh actions-lock. above it. This is a guard asking a different question from the file layout another tool produces.
    2. CodeQL (actions) dies at setup on github/codeql-action@29b1f65c1f735799893313399435a59f54045865, a pin that does not resolve upstream (seen on ai-cli-lab#12).

    Rule-suite evidence

    The technical-notes rule-suite 4313676572 has result pass and records no bypass.

    Still open after this batch

    • 21 lock-set repos have an actions.lock. Before a caller can land in them, they need lock records for the reusable and its transitive closure, verified with gh actions-lock --no-fix: cicd-suite, marches, network-outpost, residual-evidence-types, smtp-notify-action, trigger, claude-integrations, flat-mate, kitchenspeak, knot-rider, metadatastician/common-signal, academic-workflow-suite, affinescript-vite, aspasia, bitfuckit, branch-newspaper, civic-connect, defiant, ideas-to-alphas, poly-k8s-mcp, metadatastician/proglanging-languages.
    • This batch did not touch any of the following:
      • the 31 repos that are red on main (listed earlier in this issue);
      • the 92 repos with no floor (125 on the earlier list, minus the 33 floored above);
      • the 4 red caller PRs (§6c);
      • tropical-types#62, which is BLOCKED.

    🤖 Generated with Claude Code

    https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK

  2. hyperpolymath commented on Oct 1, 2026

    @hyperpolymath
    OwnerAuthor

    Correction and close-out: the 21 lock-set repos

    Correction to the earlier "Still open" item. The item said lock-set repos "need lock records for the reusable and its transitive closure". That was half wrong, in a way that mattered:

    • No lock key for the caller (cicd-suite): a job-level uses: of a reusable is not enforced by actions.lock, so the caller runs with no record at all.
    • Stale key (the other 20): these repos still had a per-workflow key '.github/workflows/secret-scanner.yml' listing the step actions of the old inline scanner. Once the workflow becomes a reusable caller, that key disagrees with it, and GitHub refuses to start the workflow: startup_failure, jobs=0. The control case is aspasia#50 before its lock commit.
    • All three local instruments pass the fatal state:
    • Cure (owner ruling D283): set that one key to [], in the same PR as the caller, as a signed createCommitOnBranch commit. Each commit was verified with the standards gate plus --no-fix.
    • bitfuckit, kitchenspeak and knot-rider: the lock was already red on main for other workflows. These were verified gate-neutral instead: the gate's finding set (severity, category, workflow) was identical before and after the edit, and no finding named secret-scanner.yml. Regenerating those locks is separate owner work.

    Result, measured 2026-10-01T23:48Z. 19 of 21 caller PRs were squash-merged by the owner (23:40–23:47Z). On all 19 merge commits the new secret-scanner.yml started (3 jobs, zero startup_failure):

    Repo PR Main secret-scanner.yml
    cicd-suite #38 green
    aspasia #50 green
    flat-mate #58 green (old duplicate secret-scan.yml still startup-fails, see below)
    marches #33 green
    residual-evidence-types #19 green
    smtp-notify-action #25 green
    affinescript-vite #48 green
    defiant #78 green
    poly-k8s-mcp #57 green
    metadatastician/proglanging-languages #5 green
    bitfuckit, kitchenspeak, knot-rider, branch-newspaper, ideas-to-alphas #80, #84, #74, #99, #93 PR runs green; main runs queued at read
    trigger #16 red — scan / gitleaks (history finding)
    academic-workflow-suite #367 red — gitleaks (JWT in a pen-test script), rust-secrets (test/bench password literals), shell-secrets (PGPASSWORD="${POSTGRES_PASSWORD:-}", likely a false positive of the shell rule)
    claude-integrations #97 red — gitleaks, 4 history hits incl. a webhook test fixture
    civic-connect #107 red on the PR run — rust-secrets ("SecurePassword123!" in crypto/mod.rs)

    The 4 reds are pre-existing repository content: each PR touched only the workflow and its lock. None of these repos has a required-status-check ruleset, so nothing deadlocks. Acceptance criteria: owner triage of each finding (rotate, allowlist, or test-fixture exemption) until main is green. No Secret-Scan-Floor is applied to these 4 before that.

    Still open:

    • network-outpost#30 and ci(secret-scan): canonical estate scanner caller, key scan (D243) metadatastician/common-signal#13 are OPEN and BLOCKED. Both have unsigned CodeRabbit autofix commits under required_signatures; common-signal also has a hypatia-scan failure.
    • flat-mate carries a second workflow, secret-scan.yml (also named "Secret Scanner", reusable @8435558, secrets: inherit, inline TruffleHog). It startup-fails on main. Acceptance criteria: delete it, and remove its lock key with the authoritative tool. This is a lock edit beyond D283's single-key approval, so it is left for the owner.

    🤖 Generated with Claude Code

    https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions