ci(secret-scanner): rename caller job key secret-scan -> scan (D243 floor) - #15
Conversation
The estate-wide Secret-Scan-Floor ruleset (D243) requires the check context `scan / gitleaks`. This caller emitted `secret-scan / gitleaks`, so no PR here could ever satisfy the floor. The reusable pin is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (3)
🔇 Additional comments (1)
📝 SummarySummary by CodeRabbit
WalkthroughThe secret-scanner workflow job key changes from ChangesSecret scanner workflow
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The rename produces the required Architecture SummaryArchitecture risk: 🔵 Low · up to The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency. Changed systems: None identified. Architecture concerns Review detailsBefore / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the scanner's name, Comment |
Why
The estate-wide Secret-Scan-Floor ruleset (owner ruling D243, ruleset
24276940on this repo) requires the status-check contextscan / gitleakson the default branch. This caller's job key wassecret-scan, so it emittedsecret-scan / gitleaks, and no PR here could satisfy the floor.Change
secret-scan:→scan:. One line.@bd0df9e…) andsecrets: inheritare unchanged.Role in the rollout
Positive-control pilot for D243. Measured: while only
scan / gitleakswas pending,mergeStateStatusread BLOCKED; once it went green, UNSTABLE. So the floor gates mergeability. This PR was not armed for auto-merge:scan / gitleakscompleted (~20–60 s) before arming could be issued, and arming an UNSTABLE PR merges it instantly. The landing form is pending an owner decision.🤖 Generated with Claude Code
https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK