Skip to content

[deep-report] Replace grep-based job/step-level secret heuristic with YAML parsing in Daily Secrets Analysis #66259

Description

@github-actions

Description

The Daily Secrets Analysis workflow's job-/step-level secret-reference split could not be computed today (#66242): "not computed (the grep heuristic from the prompt is unreliable on 323 files)". The workflow's own recommendation is to replace the grep-based heuristic with a proper YAML-parsing check, since a line-based grep can't reliably tell whether a secrets.* reference sits at job level vs step level in GitHub Actions YAML.

Expected Impact

Restores a metric the daily report currently can't produce (job-/step-level secret reference split across 323 compiled workflow lock files), making the daily secrets report more complete without changing its security posture (which is already green: 323/323 redaction, 323/323 permission blocks).

Suggested Fix

Replace the grep heuristic in the Daily Secrets Analysis workflow prompt/scripts with a YAML-aware parse (e.g. walk jobs.*.steps[] vs jobs.*.env/jobs.* top-level keys) to classify each secrets.* reference by scope.

Acceptance Criteria

  • Daily Secrets Analysis report can compute and show the job-/step-level split without the "unreliable on 323 files" caveat

Suggested Agent

Agent familiar with the Daily Secrets Analysis workflow (.github/workflows/daily-secrets-analysis.md or equivalent) and YAML parsing in the project's existing toolchain.

Estimated Effort

Quick (< 1 hour).

Data Source

Daily Secrets Analysis Report — 2026-10-06 (#66242), Recommendation #2.

Generated by 🔬 Deep Report · claude · agent · 421.8 AIC · ⌖ 9.14 AIC · ⊞ 7.1K · ◷

  • expires on Oct 8, 2026, 10:47 AM UTC-08:00

Activity

  1. github-actions commented on Oct 8, 2026

    @github-actions
    ContributorAuthor

    This issue was automatically closed because it expired on 2026-10-08T18:47:07.627Z.

    Closed by Workflow

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions