Repository navigation
feat: implement issue #408 — petry-projects — workflow failures detected 2026-05-29 - #477
Conversation
…ted 2026-05-29
|
Warning Review limit reached
More reviews will be available in 12 minutes and 37 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (2)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Code Review
This pull request introduces a .gitleaks.toml configuration file to define an allowlist for suppressing false positives in git-subtree framework imports and test fixtures. The reviewer suggested anchoring the regular expressions in the paths allowlist with ^ and $ to prevent accidental matches in other directories or files.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 83b6b0dd76
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
Pull request overview
This PR addresses issue #408 by updating the repository’s secret-scanning setup in the CI workflow, aiming to reduce workflow failures caused by gitleaks false positives and/or action behavior changes.
Changes:
- Add a repository-level
.gitleaks.tomlconfiguration intended to suppress known false positives. - Replace
gitleaks/gitleaks-actionwith a pinned, checksum-verified download/execution of the gitleaks CLI in.github/workflows/ci.yml. - Tighten CI job permissions by removing
security-events: writefrom the gitleaks job.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
.gitleaks.toml |
Introduces gitleaks configuration intended to allowlist known false positives. |
.github/workflows/ci.yml |
Switches the secret-scan job to a pinned + checksum-verified gitleaks binary download and removes unneeded permissions. |
Dev-Lead — rate-limited (intent: fix-bot-comment)PR: #477 |
|
Note @don-petry I received your request but all AI engines are currently rate-limited. Please re-mention |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: c31485a6374dd4b7b817e38b487eb25c85a33bd6
Review mode: triage-approved (single reviewer)
Summary
Replaces the gitleaks/gitleaks-action@v3 step in .github/workflows/ci.yml with a SHA256-pinned download of the gitleaks CLI (8.30.1), and adds a .gitleaks.toml config that allowlists known historical test fixtures so the full-history scan no longer fails on them. Net: +68/-7 across 2 files. Addresses fleet-monitor issue #408 (12.5% failure rate on ci.yml).
Linked issue analysis
Issue #408 is the 2026-05-29 fleet-monitor report flagging .github-private/ci.yml with a 12.5% failure rate; the gitleaks-action was a contributor to those failures. Replacing it with a pinned CLI invocation plus a scoped allowlist is a direct, proportionate fix. The "Secret scan (gitleaks)" check is now passing on this PR, confirming the new pipeline works against the full repo history.
Findings
- Security posture is solid. The CLI binary is pinned by version (
8.30.1) AND verified against an explicit SHA256 (551f6fc83ea457d62a0d98237cbad105af8d557003051f41f3e7ca7b3f2470eb) before extraction. Download uses--fail --location --retry 3 --retry-delay 5. Thesecurity-events: writepermission was correctly dropped since no SARIF is uploaded by the CLI path. .gitleaks.tomlis well-scoped. Every[[allowlists]]entry setscondition = "AND"and pairspathswith specificregexes, so only the documented historical placeholder values in the named fixture files are suppressed — a real secret in those same paths would still be flagged. This resolves the earlier advisory-bot P2 ("Require path and regex to match together") and ("Bound framework allowlist to historical findings"). The inline comment explainingcondition = "AND"is helpful.- One documented follow-up. Advisory-bot flagged that the org push-protection compliance check (
secret_scan_ci_job_presentinpetry-projects/.github/standards/push-protection.md) looks specifically forgitleaks/gitleaks-action; switching to the CLI may cause that downstream compliance audit to mark this repo as missing the secret-scan job. The PR explicitly calls this out in an inline comment pointing to the standard that needs updating. Not a blocker for merging this PR — the secret scan itself works correctly — but a follow-up is needed in thepetry-projects/.githubrepo to teach the compliance check to accept the CLI approach. - Trade-off worth noting. Without
security-events: writethe scan no longer uploads SARIF to the Security tab; findings live in workflow logs only. Reasonable for a CLI-based scan; mentioning here for awareness. - No SonarCloud/CodeQL/AgentShield issues. Quality gate passed with 0 new issues.
CI status
All 24 checks green: Lint, ShellCheck, shellcheck, bats, unit-tests, validate-agent-profiles, gh-aw-compile, Compile agentic workflows, Secret scan (gitleaks), Agent Security Scan, CodeQL (actions/python), SonarCloud, AgentShield, Dependency audit detector, dependabot-automerge (skipped as expected). The only non-success is review / review (this run, in progress).
Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
|
Review — fix requested (cycle 1/3)The automated review identified the following issues. Please address each one: Findings to fixAutomated review — NEEDS HUMAN REVIEWRisk: MEDIUM SummaryThe code-level security of this PR is sound — gitleaks CLI is pinned to v8.30.1 with SHA256 verification, downloaded over HTTPS with --fail, extracted by explicit name, and the redundant security-events: write permission is correctly dropped. The .gitleaks.toml allowlists now use condition="AND" everywhere, which is a real security improvement over the original action's globally-OR'd regexes. However, the org-wide secret_scan_ci_job_present compliance check (verified at scripts/lib/push-protection.sh:234 in petry-projects/.github, which greps for 'uses: gitleaks/gitleaks-action@' or 'zricethezav/gitleaks-action@') will silently start reporting this repo as missing the required secret-scan job, even though the scan runs correctly. The PR author chose to document the gap in an inline workflow comment rather than land the matching standards update, leaving two P2 findings open at the current head. Findings
Reviewed by the PR-review cascade (triage: haiku 4.5 → deep: sonnet 4.6 + duck: o4-mini → audit: opus 4.7). Reply if you need a human review. Additional tasks
The review cascade will automatically re-review after new commits are pushed. |



Closes #408
Implemented by dev-lead agent. Please review.