fix(ci): bump gitleaks-action v2 → v3 (Node 24 runtime; no license needed on a personal account) - #264
Conversation
v3.0.0 is a Node 20 -> Node 24 runtime migration: "No changes to inputs, outputs, or behavior." Node 24 became the default runtime for JavaScript actions on 2026-06-16 and Node 20 leaves the runners in fall 2026. No GITLEAKS_LICENSE is required here. The action's README scopes the license to organization accounts: "If you are scanning repos that belong to a personal account, then no license key is required." This repo's owner is type User. Evidence the bump is safe: v2 runs green on main today with no license (run 32684406753, job "Secret Detection (Gitleaks)" success), and v3 changes no behavior. Supersedes the equivalent change stranded in draft PR #260, which also added an unnecessary GITLEAKS_LICENSE env line. Omitted here deliberately. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013JdYCSp4nmVgsNWuwNkUaZ
📊 Code Complexity AnalysisSummary:
|
| File | Function | Complexity | Line |
|---|---|---|---|
core/risk_scorer.py |
score_pull_request |
35 | 141 |
autopilot/autopilot.py |
generate_summary |
24 | 195 |
autopilot/staleness_engine.py |
process_stale_prs |
16 | 281 |
autopilot/ai_optimization/performance_monitor.py |
get_benchmark_stats |
15 | 184 |
.github/scripts/batch_scan_dependabot.py |
main |
15 | 64 |
.github/scripts/weekly_digest.py |
build_blocks |
15 | 38 |
autopilot/recommendation_contract.py |
validate |
14 | 54 |
.github/scripts/workflow_monitor.py |
get_workflow_statistics |
14 | 216 |
.github/scripts/metrics_collector.py |
parse_workflow_metrics |
14 | 148 |
.github/scripts/setup_branch_protection.py |
main |
14 | 240 |
... and 19 more
Recommendations:
- Break down large functions into smaller, focused units
- Extract complex conditional logic into separate functions
- Use early returns to reduce nesting
🔧 Low Maintainability Files
These files have low maintainability scores and may need refactoring:
| File | Score | Status |
|---|---|---|
.github/scripts/health_dashboard_generator.py |
28.14 | 🔴 |
.github/scripts/workflow_monitor.py |
33.73 | 🔴 |
.github/scripts/ai_code_suggestor.py |
33.76 | 🔴 |
.github/scripts/ai_workflow_optimizer.py |
35.51 | 🔴 |
.github/scripts/performance_benchmark.py |
39.46 | 🔴 |
.github/scripts/self_healing_system.py |
40.27 | 🔴 |
.github/scripts/threshold_monitor.py |
41.13 | 🔴 |
.github/scripts/parallel_code_analyzer_optimized.py |
41.16 | 🔴 |
autopilot/tests/test_recommendation_contract.py |
42.05 | 🔴 |
autopilot/autopilot.py |
42.45 | 🔴 |
autopilot/ai_optimization/anomaly_detector.py |
42.56 | 🔴 |
.github/scripts/refactoring_assistant.py |
43.03 | 🔴 |
autopilot/ai_optimization/intelligent_cache.py |
43.28 | 🔴 |
autopilot/ai_optimization/commit_summarizer.py |
44.05 | 🔴 |
.github/scripts/async_parallel_analyzer.py |
44.47 | 🔴 |
autopilot/ai_optimization/performance_monitor.py |
44.69 | 🔴 |
.github/scripts/badge_generator.py |
45.28 | 🔴 |
.github/scripts/copilot_integration.py |
45.37 | 🔴 |
.github/scripts/distributed_monitoring.py |
45.53 | 🔴 |
autopilot/dependency_graph.py |
45.65 | 🔴 |
.github/scripts/elite_copilot.py |
45.69 | 🔴 |
.github/scripts/issue_auto_creator.py |
46.39 | 🔴 |
.github/scripts/cost_calculator.py |
46.4 | 🔴 |
.github/scripts/inline_pr_commenter.py |
46.63 | 🔴 |
.github/scripts/complexity_reporter.py |
46.78 | 🔴 |
.github/scripts/pr_triage.py |
47.13 | 🔴 |
core/risk_scorer.py |
48.15 | 🔴 |
autopilot/ai_optimization/nlp_relevance_filter.py |
48.43 | 🔴 |
.github/scripts/pr_inline_commenter.py |
48.47 | 🔴 |
.github/scripts/dependency_audit.py |
48.7 | 🔴 |
autopilot/staleness_engine.py |
48.73 | 🔴 |
.github/scripts/metrics_collector.py |
48.91 | 🔴 |
.github/scripts/dependency_updater.py |
48.91 | 🔴 |
autopilot/ai_optimization/ml_priority_scorer.py |
49.53 | 🔴 |
.github/scripts/parallel_code_analyzer.py |
49.96 | 🔴 |
autopilot/ai_optimization/api_optimizer.py |
50.46 | 🟡 |
.github/scripts/workflow_optimizer.py |
51.67 | 🟡 |
.github/scripts/cot_selector.py |
51.73 | 🟡 |
.github/scripts/release_manager.py |
51.92 | 🟡 |
.github/scripts/check_quality.py |
52.33 | 🟡 |
.github/scripts/auto_pr.py |
52.72 | 🟡 |
.github/scripts/changelog_generator.py |
53.13 | 🟡 |
.github/scripts/notification_manager.py |
53.58 | 🟡 |
.github/scripts/prometheus_exporter.py |
54.96 | 🟡 |
.github/scripts/weekly_digest.py |
55.02 | 🟡 |
.github/scripts/llm_router.py |
55.19 | 🟡 |
core/audit_logger.py |
55.6 | 🟡 |
.github/scripts/gather_context.py |
56.0 | 🟡 |
.github/scripts/batch_scan_dependabot.py |
56.3 | 🟡 |
core/llm_provider.py |
56.32 | 🟡 |
.github/scripts/streaming_results.py |
56.64 | 🟡 |
.github/scripts/setup_branch_protection.py |
57.0 | 🟡 |
.github/scripts/optimized_github_client.py |
58.27 | 🟡 |
agents/orchestrator_agent.py |
59.02 | 🟡 |
core/incident_freeze.py |
59.67 | 🟡 |
core/github_client.py |
61.96 | 🟡 |
core/message_queue.py |
63.22 | 🟡 |
core/agent_config.py |
63.82 | 🟡 |
autopilot/decisions/ledger.py |
63.92 | 🟡 |
core/idempotency.py |
64.45 | 🟡 |
Maintainability Index Guide:
- 🟢 85-100: Excellent maintainability
- 🟡 65-84: Good maintainability
- 🟠 50-64: Moderate maintainability (consider refactoring)
- 🔴 0-49: Poor maintainability (needs refactoring)
🟢 Risk Assessment: LOW (2.0/10)Analysed 1 files, 1+ / 1− lines. Security-sensitive paths detected. Test coverage unchanged or improved. Scoring breakdown
|
🤖 Elite AI Copilot AnalysisElite AI Copilot Analysis ReportGenerated: 2026-08-24 02:57:06 🎯 Health Score: 100.0/100🚀 Top Recommendations
📊 Detailed InsightsCode Quality Baseline Established
Security Scan Initiated
Repository Structure Analyzed
Performance Baseline Captured
Documentation Structure Good
Powered by Elite AI Copilot v1.0 |
🔒 Security Scan Results🛡️ Bandit Security Scan
📦 Dependency Vulnerabilities
Vulnerable Dependencies:
Security scans run automatically on every PR. View detailed reports in the Actions tab. |
🔍 Pre-commit Checks✅ All pre-commit checks passed! Your code follows the project style guidelines. Pre-commit hooks help maintain code quality and consistency. |
Code Quality Analysis ❌ FAILEDDuration: 0.02s Tool Results
View detailed results{
"timestamp": "2026-08-24 02:57:13",
"elapsed_seconds": 0.02,
"summary": {
"total_issues": 10,
"critical": 0,
"high": 0,
"medium": 0,
"low": 0
},
"tools": {
"pylint": {
"status": "failed",
"output": "",
"errors": "Pylint error: [Errno 2] No such file or directory: 'pylint'"
},
"flake8": {
"status": "failed",
"output": "",
"errors": "Flake8 error: [Errno 2] No such file or directory: 'flake8'"
},
"bandit": {
"status": "failed",
"output": "",
"errors": "Bandit error: [Errno 2] No such file or directory: 'bandit'"
},
"radon_cc": {
"status": "failed",
"output": "",
"errors": "Radon error: [Errno 2] No such file or directory: 'radon'"
},
"radon_mi": {
"status": "failed",
"output": "",
"errors": "Radon MI error: [Errno 2] No such file or directory: 'radon'"
}
},
"passed": false
} |
There was a problem hiding this comment.
🟢 Approval recommended
The change is a minimal, localized action version bump with no accompanying workflow logic changes, and the step configuration remains valid as written.
Pull request overview
This pull request updates the Gitleaks GitHub Action in the security scanning workflow to the v3 release, aligning the secret-scan job with the newer JavaScript-action runtime (Node 24) while keeping the job configuration unchanged (no license env var added).
Changes:
- Bump
gitleaks/gitleaks-actionfrom@v2to@v3in thesecret-scanjob. - Keep the existing environment configuration intact (only
GITHUB_TOKEN), avoiding introducing a non-existentGITLEAKS_LICENSEsecret.
File summaries
| File | Description |
|---|---|
.github/workflows/security_scan.yml |
Updates the Gitleaks action version used by the secret-scan job from v2 to v3. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
What
One line:
gitleaks/gitleaks-action@v2→@v3insecurity_scan.yml.Why now
This change has been stranded in draft PR #260 since 2026-08-22, held back by a recorded blocker:
That blocker was wrong. Verified 2026-08-24:
gh api users/labgadget015-dotcom→"type": "User". Personal account. No license required.maintoday with no license — run32684406753, job "Secret Detection (Gitleaks)" → success. v3 changes no behavior, so it will too.Deliberately NOT included
#260's version of this change also added
GITLEAKS_LICENSE: ${{ secrets.GITLEAKS_LICENSE }}to the step'senv. That line is unnecessary for a personal account and would resolve to an empty string, since the secret doesn't exist. Omitted.Node 24 context
This also counts toward #235. Node 24 became the default runtime for JavaScript actions on 2026-06-16 (already passed), and Node 20 is removed from the runners in fall 2026 — the
ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=trueopt-out stops working at removal. #235 recorded this deadline as "claims Sep 2026 — NOT independently verified"; it is real, and the first milestone is behind us.Acceptance
The
secret-scanjob must stay green. It has nocontinue-on-error, so a license failure would be loud and immediate rather than silent.Follow-up
Once this is green, draft PR #260 has nothing live left in it and can be closed unmerged and its branch deleted.
🤖 Generated with Claude Code
https://claude.ai/code/session_013JdYCSp4nmVgsNWuwNkUaZ