Repository navigation
Secret-Scan-Floor (D243/D244): sweep results and open items with acceptance criteria #1108
Description
Activity
D243 phase 2 — landing update (2026-10-01)
Landed: 77 caller PRs. All were squash-merged and all merge commits are GitHub-signed (
signature.isValid=true). That is 44 earlier and 33 in this batch.Each was merged by a literal per-PR squash command, one PR per command, and only once it was CLEAN or UNSTABLE with
scan / gitleaks= SUCCESS. None was merged while BLOCKED, and--adminwas never used.This batch (33): PR → merge commit
- ci(secret-scan): rename caller job key secret-scan -> scan (D243) awesome-ocaml#8 →
e97700306571 - ci(secret-scan): rename caller job key secret-scan -> scan (D243) awesome-provable#8 →
420018aa305d - hyperpolymath/echobox#13 →
cbe78cda2110 - ci(secret-scan): rename caller job key secret-scan -> scan (D243) hpm-http-client-rsr#11 →
ec7f1516fc51 - ci(secret-scan): rename caller job key secret-scan -> scan (D243) hpm-json-rsr#11 →
3347e4b5643d - hyperpolymath/jonathanjewell.dev#8 →
6a9e8062ef71 - ci(secret-scan): rename caller job key secret-scan -> scan (D243) veridical-simulation-core#33 →
d8014de97ed0 - ci(secret-scan): rename caller job key secret-scan -> scan (D243) metadatastician/688-attack-hub#30 →
01ebeb0b8b97 - ci(secret-scan): rename caller job key secret-scan -> scan (D243) metadatastician/berrywiki#63 →
4607ae38d81d - ci(secret-scan): rename caller job key secret-scan -> scan (D243) metadatastician/cerro-torre#58 →
ec6e0891da05 - ci(secret-scan): rename caller job key secret-scan -> scan (D243) metadatastician/f117a-stealth-glider#33 →
282da78b584b - ci(secret-scan): rename caller job key secret-scan -> scan (D243) metadatastician/f19-stealth-glider#29 →
3e75f18ce49f - ci(secret-scan): rename caller job key secret-scan -> scan (D243) metadatastician/metadatastician-governance#57 →
75f8c0983449 - ci(secret-scan): rename caller job key secret-scan -> scan (D243) metadatastician/phi-LAM#15 →
f73dc3a125e7 - ci(secret-scan): rename caller job key secret-scan -> scan (D243) metadatastician/progblocks#41 →
14136bd5b175 - ci(secret-scan): rename caller job key secret-scan -> scan (D243) metadatastician/rokur#20 →
5ab8adf0200d - ci(secret-scan): rename caller job key secret-scan -> scan (D243) metadatastician/selur#32 →
97077d35daf8 - ci(secret-scan): rename caller job key secret-scan -> scan (D243) metadatastician/vordr#35 →
d660a125f84a - ci(secret-scan): canonical estate scanner caller, key scan (D243) zerostep#102 →
c448f8f0a6ff - ci(secret-scan): canonical estate scanner caller, key scan (D243) launch-scaffolder#68 →
03ac343f3db5 - ci(secret-scan): canonical estate scanner caller, key scan (D243) me-dialect#41 →
0ed02a6b2690 - ci(secret-scan): canonical estate scanner caller, key scan (D243) not-so-serious-software#32 →
1110f2af13e7 - ci(secret-scan): canonical estate scanner caller, key scan (D243) repo-guardian#4 →
b391ccf63542 - ci(secret-scan): canonical estate scanner caller, key scan (D243) metadatastician/berrywiki-course-template#1 →
894dcdcf155b - ci(secret-scan): canonical estate scanner caller, key scan (D243) metadatastician/dosovoi#2 →
7f415e227923 - ci(secret-scan): canonical estate scanner caller, key scan (D243) metadatastician/.github#3 →
0ae3c3115c4e - ci(secret-scan): canonical estate scanner caller, key scan (D243) metadatastician/large-language-michelangelo#16 →
edd398f28c31 - ci(secret-scan): canonical estate scanner caller, key scan (D243) tentacles-agentic-syllabus#36 →
bb6f60a0f1d4 - ci(secret-scan): canonical estate scanner caller, key scan (D243) jaffascript#65 →
a4b3b8f7b2be - ci(secret-scan): canonical estate scanner caller, key scan (D243) LowLevel.jl#31 →
8ff02b59424a - ci(secret-scan): canonical estate scanner caller, key scan (D243) phantom-metal-taste#76 →
89ea6462257a - ci(secret-scan): canonical estate scanner caller, key scan (D243) polyglot-formalisms-elixir#52 →
5774bf12f100 - ci(secret-scan): canonical estate scanner caller, key scan (D243) rattlescript#83 →
421accf24be7
Red checks deferred under §5c item 3 (5 PRs)
Each PR below changes only
.github/workflows/secret-scanner.yml. The red checks on it belong to the repository, not to that change:Red check Cause Actions lockfile The grace window closed on 2026-10-01, so the check now fails Guix policy "No packaging found" Workflow security linter A scorecard.ymlpin tostandards@892497fethat predates the PR and is not an ancestor of mainClusterFuzzLite No Dockerfile Each PR has an issue with acceptance criteria, and the PR body names each red context and links that issue:
- ci(secret-scan): canonical estate scanner caller, key scan (D243) not-so-serious-software#32 → CI: 1 red check(s) on the default branch, deferred from #32 not-so-serious-software#33
- ci(secret-scan): canonical estate scanner caller, key scan (D243) tentacles-agentic-syllabus#36 → CI: 1 red check(s) on the default branch, deferred from #36 tentacles-agentic-syllabus#37
- ci(secret-scan): canonical estate scanner caller, key scan (D243) polyglot-formalisms-elixir#52 → CI: 3 red check(s) on the default branch, deferred from #52 polyglot-formalisms-elixir#53
- ci(secret-scan): canonical estate scanner caller, key scan (D243) metadatastician/dosovoi#2 → CI: 6 red check(s) on the default branch, deferred from #2 metadatastician/dosovoi#3
- ci(secret-scan): canonical estate scanner caller, key scan (D243) zerostep#102 → CI: 6 red check(s) on the default branch, deferred from #102 zerostep#103
Post-hoc App enumeration (apps-ack-gate failed open)
While the REST secondary limit is in force,
apps-ack-gatefails open: it allows the merge with the message "Apps are NOT being enumerated". That is a defect in the gate in its own right. The enumerations below were run after the merges to cover the gap.Wave 1 (8 PRs, 12:4xZ window):
- All 8 enumerated with
err=none. required_failingandrequired_absentare empty on every one.- A non-required
github-actionsFAILURE appears on 7 of them. - The legacy
hyperpolymathstatus is PENDING on ai-cli-lab#12 and cut-calculus#12. - These surface but do not block.
Wave 2 (16 PRs, 14:06–14:16Z window; enumerated after the limit cleared at 14:31Z):
- All 16 enumerated with
err=none, andrequired_failingandrequired_absentare empty on every one. - ⚠ That result is vacuous. All 16 repos had
required: []when they merged: they had no Secret-Scan-Floor yet, because they had no caller. An emptyrequired_absentover an empty required set proves nothing. (Wave 1's 8 do carryrequired: ["scan / gitleaks"], so their result is real.) - A non-required
github-actionsFAILURE appears on jaffascript#65, LowLevel.jl#31 and phantom-metal-taste#76, plus the 5 deferred above.hyperpolymathstatus is PENDING on launch-scaffolder#68 and LowLevel.jl#31.
Floors now applied to all 33 repos in this batch.
- Before creating each floor, I read
scan / gitleakson the default-branch head. It was SUCCESS on all 33, so no floor creates a deadlock. createRepositoryRulesetreturned CREATED 33/33.rules/branches/<default>now returnsrequired_status_checks = scan / gitleakson 33/33.
§5c deferrals for the remaining reds (10 PRs). Each issue lists every red context on the PR head, gives a diagnosed cause where one was read, and states acceptance criteria. Each PR body links its issue:
PR Issue Reds hyperpolymath/jaffascript#65 hyperpolymath/jaffascript#66 1 hyperpolymath/LowLevel.jl#31 hyperpolymath/LowLevel.jl#32 4 hyperpolymath/phantom-metal-taste#76 hyperpolymath/phantom-metal-taste#77 2 hyperpolymath/bebop-ffi#82 hyperpolymath/bebop-ffi#83 2 hyperpolymath/info#15 hyperpolymath/info#16 4 hyperpolymath/trope-checker#96 hyperpolymath/trope-checker#97 9 hyperpolymath/trope-particularity-workbench#73 hyperpolymath/trope-particularity-workbench#74 5 hyperpolymath/awesome-haskell#14 hyperpolymath/awesome-haskell#15 2 hyperpolymath/ai-cli-lab#12 hyperpolymath/ai-cli-lab#13 2 hyperpolymath/cut-calculus#12 hyperpolymath/cut-calculus#13 2 Two estate-wide causes were found along the way. Each needs its own standards fix:
- Workflow security lint (
lint-workflows) flags every workflow in a repo thatgh actions-lockmanages. The linter requires# SPDX-License-Identifier:on line 1, but actions-lock writes# This workflow is managed by gh actions-lock.above it. This is a guard asking a different question from the file layout another tool produces. - CodeQL (actions) dies at setup on
github/codeql-action@29b1f65c1f735799893313399435a59f54045865, a pin that does not resolve upstream (seen on ai-cli-lab#12).
Rule-suite evidence
The technical-notes rule-suite
4313676572has resultpassand records no bypass.Still open after this batch
- 21 lock-set repos have an
actions.lock. Before a caller can land in them, they need lock records for the reusable and its transitive closure, verified withgh actions-lock --no-fix: cicd-suite, marches, network-outpost, residual-evidence-types, smtp-notify-action, trigger, claude-integrations, flat-mate, kitchenspeak, knot-rider, metadatastician/common-signal, academic-workflow-suite, affinescript-vite, aspasia, bitfuckit, branch-newspaper, civic-connect, defiant, ideas-to-alphas, poly-k8s-mcp, metadatastician/proglanging-languages. - This batch did not touch any of the following:
- the 31 repos that are red on main (listed earlier in this issue);
- the 92 repos with no floor (125 on the earlier list, minus the 33 floored above);
- the 4 red caller PRs (§6c);
- tropical-types#62, which is BLOCKED.
🤖 Generated with Claude Code
- ci(secret-scan): rename caller job key secret-scan -> scan (D243) awesome-ocaml#8 →
Correction and close-out: the 21 lock-set repos
Correction to the earlier "Still open" item. The item said lock-set repos "need lock records for the reusable and its transitive closure". That was half wrong, in a way that mattered:
- No lock key for the caller (cicd-suite): a job-level
uses:of a reusable is not enforced byactions.lock, so the caller runs with no record at all. - Stale key (the other 20): these repos still had a per-workflow key
'.github/workflows/secret-scanner.yml'listing the step actions of the old inline scanner. Once the workflow becomes a reusable caller, that key disagrees with it, and GitHub refuses to start the workflow: startup_failure, jobs=0. The control case is aspasia#50 before its lock commit. - All three local instruments pass the fatal state:
check-actions-lock-gate.shgives rc=0. It can fail: a planted unlocked step gave rc=1.gh actions-lock --no-fixgives valid=true.- Targeted
gh actions-lock <wf>(v0.1.6) does not reset the key. - Upstream: v0.1.6: job-level reusable-workflow
uses:refs are invisible — missed desync, falsestale, and fix mode prunes a correct entry github/gh-actions-lock#129.
- Cure (owner ruling D283): set that one key to
[], in the same PR as the caller, as a signedcreateCommitOnBranchcommit. Each commit was verified with the standards gate plus--no-fix. - bitfuckit, kitchenspeak and knot-rider: the lock was already red on main for other workflows. These were verified gate-neutral instead: the gate's finding set (severity, category, workflow) was identical before and after the edit, and no finding named
secret-scanner.yml. Regenerating those locks is separate owner work.
Result, measured 2026-10-01T23:48Z. 19 of 21 caller PRs were squash-merged by the owner (23:40–23:47Z). On all 19 merge commits the new
secret-scanner.ymlstarted (3 jobs, zero startup_failure):Repo PR Main secret-scanner.ymlcicd-suite #38 green aspasia #50 green flat-mate #58 green (old duplicate secret-scan.ymlstill startup-fails, see below)marches #33 green residual-evidence-types #19 green smtp-notify-action #25 green affinescript-vite #48 green defiant #78 green poly-k8s-mcp #57 green metadatastician/proglanging-languages #5 green bitfuckit, kitchenspeak, knot-rider, branch-newspaper, ideas-to-alphas #80, #84, #74, #99, #93 PR runs green; main runs queued at read trigger #16 red — scan / gitleaks(history finding)academic-workflow-suite #367 red — gitleaks (JWT in a pen-test script), rust-secrets (test/bench password literals), shell-secrets ( PGPASSWORD="${POSTGRES_PASSWORD:-}", likely a false positive of the shell rule)claude-integrations #97 red — gitleaks, 4 history hits incl. a webhook test fixture civic-connect #107 red on the PR run — rust-secrets ( "SecurePassword123!"incrypto/mod.rs)The 4 reds are pre-existing repository content: each PR touched only the workflow and its lock. None of these repos has a required-status-check ruleset, so nothing deadlocks. Acceptance criteria: owner triage of each finding (rotate, allowlist, or test-fixture exemption) until main is green. No Secret-Scan-Floor is applied to these 4 before that.
Still open:
- network-outpost#30 and ci(secret-scan): canonical estate scanner caller, key scan (D243) metadatastician/common-signal#13 are OPEN and BLOCKED. Both have unsigned CodeRabbit autofix commits under
required_signatures; common-signal also has a hypatia-scan failure. - flat-mate carries a second workflow,
secret-scan.yml(also named "Secret Scanner", reusable @8435558,secrets: inherit, inline TruffleHog). It startup-fails on main. Acceptance criteria: delete it, and remove its lock key with the authoritative tool. This is a lock edit beyond D283's single-key approval, so it is left for the owner.
🤖 Generated with Claude Code
- No lock key for the caller (cicd-suite): a job-level
Context
D243/D244 (owner ruling 2026-10-01) put an estate-wide Secret-Scan-Floor ruleset on every non-vault, non-fork repo whose default head emits
scan / gitleaks: 336 repos (first pass: 312 created and 2 already present; second pass: 21 created and 1 already present). The 103 repos that do not yet emit the context have no floor, because a floor there would block every PR. Section 2, section 3 and the B-shape rename backlog cover them. The ruleset requires the contextscan / gitleaks(integration 15368, admin-role bypass, target~DEFAULT_BRANCH). The callers were made to emit that context by renaming the job keysecret-scan→scanand by writing the canonical caller (secret-scanner-reusable.yml@74d2f66).What landed and what is still open is recorded below. Each item that the sweep could not close is listed with acceptance criteria. Per the 09-15 standing ruling, a scanner finding is an issue, not a blocker.
Horizon: every measurement below is from the GraphQL API on 2026-10-01 between 12:00Z and 13:45Z, over the 439 repos of
hyperpolymath+metadatasticianthat are not archived. The 3 gcrypt vaults and 5 forks were excluded by name.1. Default branches RED at gitleaks — 31 repos (possible committed secrets)
Re-measured at each default-branch head (not the census snapshot). The gating gitleaks pass in
secret-scanner-reusable.yml@74d2f66scans the full history (fetch-depth: 0, it refuses a shallow clone, and its own comment says "The gate is full-history"). So on these repos every PR is red atscan / gitleakstoo. 21 of them now carry the floor, which the owner accepted: their PRs are blocked until the finding is triaged, or merged by an admin bypass. The repos:hyperpolymath/boj-server @ 0ba6a6c4hyperpolymath/panic-attack @ 5ee25658hyperpolymath/poly-observability-mcp @ 6fa74f22hyperpolymath/panll @ 03583e9ahyperpolymath/nickel-augmentation @ 77e39f76hyperpolymath/lcb-website @ 345431e8hyperpolymath/januskey @ fd0c56f9hyperpolymath/hyperpolymath-sovereign-registry @ 89847c6ahyperpolymath/hpm-crypto-rsr @ f1e42c97hyperpolymath/frayed-knot-toolkit @ 07798e2ahyperpolymath/laminar @ 582aa532hyperpolymath/email-octad-experiment @ 5cd67a27hyperpolymath/lithoglyph @ ba7ebe20hyperpolymath/boj-server-cartridges @ 50b1af4chyperpolymath/contractiles-a2-lab @ 5943ae6bhyperpolymath/blog-drafts @ 8c545cb2hyperpolymath/007-lang @ 61054841hyperpolymath/ipv6-tools @ 632bb26bhyperpolymath/jtv-halting-islands-ct @ b41e29d1hyperpolymath/zotero-tools @ 0a00bcfbhyperpolymath/claude-memory @ 1299ac9bhyperpolymath/typefix-zero @ ae598741hyperpolymath/echobox @ bf6371bchyperpolymath/veridical-simulation-core @ 7b8297b3hyperpolymath/jewell.nexus @ 48e66fdbhyperpolymath/axel-protocol @ 9d077309hyperpolymath/jonathanjewell.dev @ 56528d60hyperpolymath/hpm-github-api-rsr @ 8274b3d5metadatastician/insolvency-tycoon @ 4c52759ametadatastician/enaction-engine @ 9165cf5dmetadatastician/burble @ b36f142aEach repo: triage the gitleaks finding(s) on main. Either rotate and purge the secret, or add a reviewed
.gitleaksignoreentry naming the fingerprint and the reason.scan / gitleaks(orsecret-scan / gitleaks) is SUCCESS on the default-branch head.2. Repos with
actions.lock— caller not yet written (21)The canonical caller calls
hyperpolymath/standards@74d2f66…, whose job usesactions/checkout@3d3c42e5…. A lock that lacks either record startup-kills the caller. Repos:hyperpolymath/cicd-suite,hyperpolymath/marches,hyperpolymath/network-outpost,hyperpolymath/residual-evidence-types,hyperpolymath/smtp-notify-action,hyperpolymath/trigger,hyperpolymath/claude-integrations,hyperpolymath/flat-mate,hyperpolymath/kitchenspeak,hyperpolymath/knot-rider,metadatastician/common-signal,hyperpolymath/academic-workflow-suite,hyperpolymath/affinescript-vite,hyperpolymath/aspasia,hyperpolymath/bitfuckit,hyperpolymath/branch-newspaper,hyperpolymath/civic-connect,hyperpolymath/defiant,hyperpolymath/ideas-to-alphas,hyperpolymath/poly-k8s-mcp,metadatastician/proglanging-languages.proglanging-languageshas an open PR (#3, the old pin@bd0df9eawith a lock missing a checkout record, so it startup-fails), which will be reworked under this item.gh actions-lockgains callee-aware generation: locking a workflow that calls a reusable also records the reusable's ownuses:(transitively closed).gh actions-lock --no-fix(not a hand-rolled check) before the PR opens.@84355587with an extra inline trufflehog job and a lock missingactions/checkout@3d3c42e5) is covered by the same fix.3. Private repos — Actions availability unproven (6)
hyperpolymath/lfs-shared,hyperpolymath/linguist,hyperpolymath/multiterm,metadatastician/bowtie-workbench,metadatastician/reflexive-ai-studio,hyperpolymath/polystack— no caller was written. If Actions cannot run (billing), a floor deadlocks every PR.4. Phantom and dead reusable pins
metadatastician/common-signal:secret-scanner.ymlpins@5b1d0022, which does not exist inhyperpolymath/standards("failed to fetch workflow"). Its lock entry for the file is[].@892497feand@7fdc2705fail with "error parsing called workflow … workflow was not found".5. Rulesets that already require the OLD context — irreversible-cutover shape
epistemic-types(secret-scan / gitleaks),deed-ecosystem(secret-scan / gitleaks,rust-secrets,shell-secrets),firmboot(firmboot-continuity-proof-branchrequiressecret-scan / gitleaks). Renaming the key here deadlocks every PR until the ruleset changes.updateRepositoryRulesetswapping the contexts toscan / …, then merge.6. Invalid caller files (never ran)
proglanging-languages:timeout-minuteson a reusable-call job (fixed by ci(secret-scan): rename key to scan, drop invalid timeout-minutes (D243) metadatastician/proglanging-languages#3).kitchenspeak(same defect),tentacles-agentic-syllabus(indentation makespermissionsa job key),affinescript-vite/bitfuckit/phantom-metal-taste(hashFiles()in a job-levelif).6a. Startup failures unrelated to the caller (17 INSPECT rows)
the-nash-equilibrium(guard-defective, do not merge) andaffinescript(a deliberately inlinescanjob that emits a barescan) were left alone on purpose.scan / gitleaksreports on the default head.6b. The reusable's header still says
secrets: inheritis REQUIRED — false at @74d2f66.github/workflows/secret-scanner-reusable.ymllines 32-35 tell callers to passsecrets: inherit, or else "the gitleaks action's innersecrets.GITHUB_TOKENis empty". At74d2f66the reusable has no${{ secrets.* }}reference, and gitleaks runs as a checksum-verified binary (line 45 says it replacedgitleaks/gitleaks-action). Sosecrets: inheritonly forwards every repo and org secret to it (CWE-250). CodeRabbit (oikosbot-estate#3) and Hypatia WH008 (launch-scaffolder#68) both flagged it.This sweep's caller template copied the false note. It was corrected in all 26 caller PRs and in zerostep#102, each by a second signed commit. Positive control: zerostep#102 went green on all three
scan /jobs with no secrets passed.secrets: inheritinstruction and says the caller needs nosecrets:line.secrets: inheritto this reusable are listed and dropped (a census keyed on content).6c. New caller PRs RED at gitleaks (4)
These PRs only add or replace the caller file. Their
scan / gitleaksis FAILURE on the PR head. The gating pass scans the full history, so the finding is almost certainly pre-existing history these repos had never scanned, not the PR diff (triage pending): hyperpolymath/ambientops#381, hyperpolymath/palimpsest-license#161, metadatastician/project-ovine#34, hyperpolymath/misinformation-defence-platform#85. Each repo's default branch had no running scanner before (ADD/BUMP/REPLACE), so this is likely the first scan these repos have had..gitleaksignoreentry), and the PR goes green and lands.6d. Caller PRs BLOCKED by non-check rules (7)
All 7 have
scan / gitleaks= SUCCESS. Each is blocked by another rule type:secrets: inherit) was fixed and resolved, and the review now needs re-evaluation or dismissal.rules/branches/{base}, then satisfied or waived by the owner.7. Default branch ≠ trigger branch
HOL(defaultdevelop, trigger[main, master]) andrescript(defaultci/burn-reduction-triggers-concurrency). No scanner context ever lands on the default branch.8. Tooling/process defects found during the sweep
rate_limitreading 5000 remaining, 0 used), the enumerator returned{"error":"cannot read … pulls/N"}with rc=0. The hook'sbail()then allowed the merge on its first call, with no ack table. 8 merges ran without App enumeration:hyperpolymath/bebop-ffi#82,hyperpolymath/awesome-agda#8,hyperpolymath/info#15,hyperpolymath/trope-checker#96,hyperpolymath/trope-particularity-workbench#73,hyperpolymath/awesome-haskell#14,hyperpolymath/ai-cli-lab#12,hyperpolymath/cut-calculus#12. All 8 landed GitHub-signed; post-hoc enumeration: pending: the REST secondary limit was still active at 13:18Z. Results will be posted as a comment on this issue..rate_limitcannot see the secondary limit. Any pacing that readscore.remainingwill keep hammering.retry-after, not onrate_limit.secret-scan.yml) and firmboot (secrets.yml) as having no caller.secret-scanner-reusable.yml@), not on the filename.Landed in this sweep
scan(D243 floor) pseudoscript#62🤖 Generated with Claude Code
https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK