Skip to content

fix(ci): bump gitleaks-action v2 → v3 (Node 24 runtime; no license needed on a personal account) - #264

Merged
labgadget015-dotcom merged 1 commit into
mainfrom
fix/gitleaks-action-v3
Aug 24, 2026
Merged

fix(ci): bump gitleaks-action v2 → v3 (Node 24 runtime; no license needed on a personal account)#264
labgadget015-dotcom merged 1 commit into
mainfrom
fix/gitleaks-action-v3

Conversation

@labgadget015-dotcom

Copy link
Copy Markdown
Owner

What

One line: gitleaks/gitleaks-action@v2@v3 in security_scan.yml.

Why now

This change has been stranded in draft PR #260 since 2026-08-22, held back by a recorded blocker:

"DO NOT cherry-pick it blind. v3 also injects GITLEAKS_LICENSE, a secret that does NOT exist on this repo, and the gitleaks step sits in job secret-scan with NO continue-on-error. A blind bump reddens main."

That blocker was wrong. Verified 2026-08-24:

  • The action's README scopes the license to organizations: "If you are scanning repos that belong to an organization account, you will need to obtain a free license key. If you are scanning repos that belong to a personal account, then no license key is required."
  • gh api users/labgadget015-dotcom"type": "User". Personal account. No license required.
  • v3.0.0's release notes describe a Node 20 → Node 24 runtime migration with "No changes to inputs, outputs, or behavior."
  • Strongest evidence: v2 runs green on main today with no license — run 32684406753, job "Secret Detection (Gitleaks)" → success. v3 changes no behavior, so it will too.

Deliberately NOT included

#260's version of this change also added GITLEAKS_LICENSE: ${{ secrets.GITLEAKS_LICENSE }} to the step's env. That line is unnecessary for a personal account and would resolve to an empty string, since the secret doesn't exist. Omitted.

Node 24 context

This also counts toward #235. Node 24 became the default runtime for JavaScript actions on 2026-06-16 (already passed), and Node 20 is removed from the runners in fall 2026 — the ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true opt-out stops working at removal. #235 recorded this deadline as "claims Sep 2026 — NOT independently verified"; it is real, and the first milestone is behind us.

Acceptance

The secret-scan job must stay green. It has no continue-on-error, so a license failure would be loud and immediate rather than silent.

Follow-up

Once this is green, draft PR #260 has nothing live left in it and can be closed unmerged and its branch deleted.

🤖 Generated with Claude Code

https://claude.ai/code/session_013JdYCSp4nmVgsNWuwNkUaZ

v3.0.0 is a Node 20 -> Node 24 runtime migration: "No changes to inputs, outputs, or behavior." Node 24 became the default runtime for JavaScript actions on 2026-06-16 and Node 20 leaves the runners in fall 2026.

No GITLEAKS_LICENSE is required here. The action's README scopes the license to organization accounts: "If you are scanning repos that belong to a personal account, then no license key is required." This repo's owner is type User.

Evidence the bump is safe: v2 runs green on main today with no license (run 32684406753, job "Secret Detection (Gitleaks)" success), and v3 changes no behavior.

Supersedes the equivalent change stranded in draft PR #260, which also added an unnecessary GITLEAKS_LICENSE env line. Omitted here deliberately.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013JdYCSp4nmVgsNWuwNkUaZ
Copilot AI lite review requested due to automatic review settings August 24, 2026 02:56
@github-actions

Copy link
Copy Markdown
Contributor

📊 Code Complexity Analysis

Summary:

  • Total Functions Analyzed: 844
  • Average Complexity: 3.59
  • High Complexity Functions: 29
  • Low Maintainability Files: 60

⚠️ High Complexity Functions

These functions exceed the complexity threshold and should be refactored:

File Function Complexity Line
core/risk_scorer.py score_pull_request 35 141
autopilot/autopilot.py generate_summary 24 195
autopilot/staleness_engine.py process_stale_prs 16 281
autopilot/ai_optimization/performance_monitor.py get_benchmark_stats 15 184
.github/scripts/batch_scan_dependabot.py main 15 64
.github/scripts/weekly_digest.py build_blocks 15 38
autopilot/recommendation_contract.py validate 14 54
.github/scripts/workflow_monitor.py get_workflow_statistics 14 216
.github/scripts/metrics_collector.py parse_workflow_metrics 14 148
.github/scripts/setup_branch_protection.py main 14 240

... and 19 more

Recommendations:

  • Break down large functions into smaller, focused units
  • Extract complex conditional logic into separate functions
  • Use early returns to reduce nesting

🔧 Low Maintainability Files

These files have low maintainability scores and may need refactoring:

File Score Status
.github/scripts/health_dashboard_generator.py 28.14 🔴
.github/scripts/workflow_monitor.py 33.73 🔴
.github/scripts/ai_code_suggestor.py 33.76 🔴
.github/scripts/ai_workflow_optimizer.py 35.51 🔴
.github/scripts/performance_benchmark.py 39.46 🔴
.github/scripts/self_healing_system.py 40.27 🔴
.github/scripts/threshold_monitor.py 41.13 🔴
.github/scripts/parallel_code_analyzer_optimized.py 41.16 🔴
autopilot/tests/test_recommendation_contract.py 42.05 🔴
autopilot/autopilot.py 42.45 🔴
autopilot/ai_optimization/anomaly_detector.py 42.56 🔴
.github/scripts/refactoring_assistant.py 43.03 🔴
autopilot/ai_optimization/intelligent_cache.py 43.28 🔴
autopilot/ai_optimization/commit_summarizer.py 44.05 🔴
.github/scripts/async_parallel_analyzer.py 44.47 🔴
autopilot/ai_optimization/performance_monitor.py 44.69 🔴
.github/scripts/badge_generator.py 45.28 🔴
.github/scripts/copilot_integration.py 45.37 🔴
.github/scripts/distributed_monitoring.py 45.53 🔴
autopilot/dependency_graph.py 45.65 🔴
.github/scripts/elite_copilot.py 45.69 🔴
.github/scripts/issue_auto_creator.py 46.39 🔴
.github/scripts/cost_calculator.py 46.4 🔴
.github/scripts/inline_pr_commenter.py 46.63 🔴
.github/scripts/complexity_reporter.py 46.78 🔴
.github/scripts/pr_triage.py 47.13 🔴
core/risk_scorer.py 48.15 🔴
autopilot/ai_optimization/nlp_relevance_filter.py 48.43 🔴
.github/scripts/pr_inline_commenter.py 48.47 🔴
.github/scripts/dependency_audit.py 48.7 🔴
autopilot/staleness_engine.py 48.73 🔴
.github/scripts/metrics_collector.py 48.91 🔴
.github/scripts/dependency_updater.py 48.91 🔴
autopilot/ai_optimization/ml_priority_scorer.py 49.53 🔴
.github/scripts/parallel_code_analyzer.py 49.96 🔴
autopilot/ai_optimization/api_optimizer.py 50.46 🟡
.github/scripts/workflow_optimizer.py 51.67 🟡
.github/scripts/cot_selector.py 51.73 🟡
.github/scripts/release_manager.py 51.92 🟡
.github/scripts/check_quality.py 52.33 🟡
.github/scripts/auto_pr.py 52.72 🟡
.github/scripts/changelog_generator.py 53.13 🟡
.github/scripts/notification_manager.py 53.58 🟡
.github/scripts/prometheus_exporter.py 54.96 🟡
.github/scripts/weekly_digest.py 55.02 🟡
.github/scripts/llm_router.py 55.19 🟡
core/audit_logger.py 55.6 🟡
.github/scripts/gather_context.py 56.0 🟡
.github/scripts/batch_scan_dependabot.py 56.3 🟡
core/llm_provider.py 56.32 🟡
.github/scripts/streaming_results.py 56.64 🟡
.github/scripts/setup_branch_protection.py 57.0 🟡
.github/scripts/optimized_github_client.py 58.27 🟡
agents/orchestrator_agent.py 59.02 🟡
core/incident_freeze.py 59.67 🟡
core/github_client.py 61.96 🟡
core/message_queue.py 63.22 🟡
core/agent_config.py 63.82 🟡
autopilot/decisions/ledger.py 63.92 🟡
core/idempotency.py 64.45 🟡

Maintainability Index Guide:

  • 🟢 85-100: Excellent maintainability
  • 🟡 65-84: Good maintainability
  • 🟠 50-64: Moderate maintainability (consider refactoring)
  • 🔴 0-49: Poor maintainability (needs refactoring)

@github-actions github-actions Bot added the ci/cd label Aug 24, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🟢 Risk Assessment: LOW (2.0/10)

Analysed 1 files, 1+ / 1− lines. Security-sensitive paths detected. Test coverage unchanged or improved.

Scoring breakdown

Factor Score
Sensitive paths — 1 security-relevant files +1.5
Risky extensions — 1 config/script files +0.5

⚠️ Security-sensitive paths modified

  • .github/workflows/security_scan.yml

✅ Eligible for auto-merge (subject to CI passing).

@github-actions

Copy link
Copy Markdown
Contributor

🤖 Elite AI Copilot Analysis

Elite AI Copilot Analysis Report

Generated: 2026-08-24 02:57:06
Session ID: copilot_1787540226
Repository: .

🎯 Health Score: 100.0/100

🚀 Top Recommendations

  1. ✅ Repository is in excellent shape - continue current practices

📊 Detailed Insights

Code Quality Baseline Established

  • Category: code_quality
  • Severity: info
  • Description: Repository code quality metrics captured
  • Suggested Action: Continue monitoring for regressions
  • Confidence: 90%

Security Scan Initiated

  • Category: security
  • Severity: info
  • Description: No critical vulnerabilities detected in initial scan
  • Suggested Action: Enable continuous security monitoring
  • Confidence: 85%

Repository Structure Analyzed

  • Category: architecture
  • Severity: info
  • Description: Well-organized modular structure detected
  • Suggested Action: Maintain separation of concerns
  • Confidence: 80%

Performance Baseline Captured

  • Category: performance
  • Severity: info
  • Description: Repository performance metrics recorded
  • Suggested Action: Monitor for performance regressions
  • Confidence: 75%

Documentation Structure Good

  • Category: documentation
  • Severity: info
  • Description: Comprehensive documentation files present
  • Suggested Action: Keep documentation in sync with code changes
  • Confidence: 90%

Powered by Elite AI Copilot v1.0

@github-actions

Copy link
Copy Markdown
Contributor

🔒 Security Scan Results

🛡️ Bandit Security Scan

  • 🔴 HIGH: 0
  • 🟡 MEDIUM: 5
  • 🟢 LOW: 107

📦 Dependency Vulnerabilities

  • Total vulnerable dependencies: 61

Vulnerable Dependencies:

  • pygithub 2.10.0
  • aiohttp 3.14.3
  • multidict 6.7.1
  • yarl 1.24.5
  • pyyaml 6.0.3
  • ... and 56 more

Security scans run automatically on every PR. View detailed reports in the Actions tab.

@github-actions

Copy link
Copy Markdown
Contributor

🔍 Pre-commit Checks

✅ All pre-commit checks passed!

Your code follows the project style guidelines.


Pre-commit hooks help maintain code quality and consistency.

@github-actions

Copy link
Copy Markdown
Contributor

Code Quality Analysis ❌ FAILED

Duration: 0.02s
Total Issues: 10

Tool Results

  • pylint: ❌
  • flake8: ❌
  • bandit: ❌
  • radon_cc: ❌
  • radon_mi: ❌
View detailed results
{
  "timestamp": "2026-08-24 02:57:13",
  "elapsed_seconds": 0.02,
  "summary": {
    "total_issues": 10,
    "critical": 0,
    "high": 0,
    "medium": 0,
    "low": 0
  },
  "tools": {
    "pylint": {
      "status": "failed",
      "output": "",
      "errors": "Pylint error: [Errno 2] No such file or directory: 'pylint'"
    },
    "flake8": {
      "status": "failed",
      "output": "",
      "errors": "Flake8 error: [Errno 2] No such file or directory: 'flake8'"
    },
    "bandit": {
      "status": "failed",
      "output": "",
      "errors": "Bandit error: [Errno 2] No such file or directory: 'bandit'"
    },
    "radon_cc": {
      "status": "failed",
      "output": "",
      "errors": "Radon error: [Errno 2] No such file or directory: 'radon'"
    },
    "radon_mi": {
      "status": "failed",
      "output": "",
      "errors": "Radon MI error: [Errno 2] No such file or directory: 'radon'"
    }
  },
  "passed": false
}

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is a minimal, localized action version bump with no accompanying workflow logic changes, and the step configuration remains valid as written.

Pull request overview

This pull request updates the Gitleaks GitHub Action in the security scanning workflow to the v3 release, aligning the secret-scan job with the newer JavaScript-action runtime (Node 24) while keeping the job configuration unchanged (no license env var added).

Changes:

  • Bump gitleaks/gitleaks-action from @v2 to @v3 in the secret-scan job.
  • Keep the existing environment configuration intact (only GITHUB_TOKEN), avoiding introducing a non-existent GITLEAKS_LICENSE secret.
File summaries
File Description
.github/workflows/security_scan.yml Updates the Gitleaks action version used by the secret-scan job from v2 to v3.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@labgadget015-dotcom
labgadget015-dotcom merged commit b99e5c8 into main Aug 24, 2026
39 checks passed
@labgadget015-dotcom
labgadget015-dotcom deleted the fix/gitleaks-action-v3 branch August 24, 2026 02:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants