Skip to content

Estate drift: unresolvable trufflehog action pin (@7ee2e0fd… # main) breaks quality/lint estate-wide #82

Description

@hyperpolymath

Sub-issue of #66 (2026-05-16 sweep findings — surfaced again 2026-05-17 via the burble#35 SARIF PRs).

Symptom

lint / quality job fails at Set up job (before any step runs):

Unable to resolve action `trufflesecurity/trufflehog@7ee2e0fdffec27d19ccbb8fb3dcf8a83b9d7f9e8`, unable to find version `7ee2e0fdffec27d19ccbb8fb3dcf8a83b9d7f9e8`

The step has continue-on-error: true, but action resolution happens before the step, so the whole job goes red regardless. This is a hard estate-wide baseline red, not advisory.

Root cause

quality.yml pins trufflesecurity/trufflehog@7ee2e0fdffec27d19ccbb8fb3dcf8a83b9d7f9e8 # main — i.e. a SHA captured from upstream's moving main branch. Upstream GC'd / rewrote it, so the SHA no longer resolves. Pinning @<sha> # main is itself the anti-pattern: pin to a released tag SHA, never a moving ref's transient SHA.

Canonical home + blast radius (confirmed local clones)

Canonical quality.yml lives in reposystem and v3-templater. Bad SHA 7ee2e0fd… confirmed in:

  • v3-templater/.github/workflows/quality.yml:19 ( # main)
  • repos/verisimdb/.github/workflows/quality.yml:69 ( # main)
  • repos/ochrance/.github/workflows/secret-scanner.yml:22 ( # v3 — mislabelled, same bad SHA)
  • (+ every consumer that adopted quality.yml / secret-scanner.yml)

Fix

  1. Repin to a real released-tag SHA. Known-good pins already in the estate:
    • trufflesecurity/trufflehog@05cccb53bc9e13bc6d17997db5a6bcc3df44bf2f # v3.92.3 (deterministic, preferred)
    • or …@6c05c4a00b91aa542267d8e32a8254774799d68d # v3
  2. Apply at canonical (reposystem + v3-templater quality.yml, and secret-scanner.yml where the same mislabelled pin exists), then consumer sweep per the [drift playbook].
  3. Add a lint rule / grep guard rejecting @<sha> # main|master|HEAD pins so this class can't recur (Explicit-Escape / truth-in-pinning).

Refs #66

Activity

  1. hyperpolymath commented on May 27, 2026

    @hyperpolymath
    OwnerAuthor

    Closing as resolved by canonical-workflow migration.

    Evidence:

    1. v3-templater quality.yml no longer uses trufflesecurity/trufflehog at all — migrated to Deno-based quality checks (deno lint / deno fmt / TODO marker grep). Verified via Contents API on main, sha 556e76e.
    2. reposystem no longer carries a .github/workflows/quality.yml (404 from Contents API), so the canonical scaffolding source is clean.
    3. verisimdb quality.yml likewise 404 — repo no longer has the file.
    4. Active root-level .github/workflows/secret-scanner.yml workflows in all consumer repos use the standards reusable (PR feat(governance): add secret-scanner-reusable.yml — propagate shell-secrets to 281 repos #190 secret-scanner-reusable.yml — MERGED 2026-05-26, 281/281 sweep complete per [[session-2026-05-26-reusables-campaign]]). Verified maa-framework/.github/workflows/secret-scanner.yml and stapeln/.github/workflows/secret-scanner.yml no longer reference trufflehog directly.
    5. Bad SHA 7ee2e0fdffec27d19ccbb8fb3dcf8a83b9d7f9e8 only persists in non-active vendored sub-paths (maa-framework/aletheia/.github/workflows/secret-scanner.yml, stapeln/container-stack/svalinn/.github/workflows/secret-scanner.yml) — those are inside nested project directories, not active workflows. gh api repos/{maa-framework,stapeln}/actions/workflows confirms only the root-level secret-scanner is wired.

    Residual occurrences are all benign: 5 docs/scripts/historical references (CHANGELOG/SECURITY.md/audit-report) + 3 lookup tables in hypatia/scripts/fix-*.sh and scripts/fix-unpinned-actions.sh which encode the bad-SHA as the source pattern that the auto-fix REWRITES. No active workflow consumes the bad SHA.

    Refs #66 (parent sweep), #190 (reusable propagation).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions