ci: complete Wave 4 security migration - #81
Conversation
|
|
||
| jobs: | ||
| analyze: | ||
| name: Analyze (${{ matrix.language }}) |
There was a problem hiding this comment.
🟡 Required CodeQL checks disappear
Deleting CodeQL Advanced removes the three Analyze (...) checks still required by the main-branch ruleset. Default Setup reports CodeQL, so future pull requests cannot satisfy the ruleset or merge.
Learn more
The repository ruleset currently requires Analyze (python), Analyze (javascript-typescript), and Analyze (actions). Those contexts come from this workflow's matrix job. GitHub CodeQL Default Setup produces a single CodeQL check instead, so deleting the workflow does not migrate the required status checks.
Example: After this PR merges, a new pull request receives a successful CodeQL result. The ruleset still waits indefinitely for all three Analyze (...) results, which no active workflow can create.
Recommended fix: Update the main-branch ruleset to require the Default Setup CodeQL context before deleting this workflow. Keep the old workflow active until that external migration is complete if the ruleset cannot be changed atomically.
Was this helpful? React with 👍 or 👎 to provide feedback.
| name: "CodeQL Advanced" | ||
|
|
||
| on: | ||
| push: | ||
| branches: ["main"] | ||
| pull_request: | ||
| branches: ["main"] |
There was a problem hiding this comment.
Completes the Wave 4 security-engine migration for this repository:\n\n- add weekly advisory OpenSSF Scorecard with full-SHA-pinned actions and SARIF upload\n- keep Scorecard results private to GitHub Code Scanning (
publish_results: false)\n- remove the now-disabled Advanced CodeQL workflow after successful migration to GitHub CodeQL Default Setup\n- add advisory Trivy filesystem scanning for dependency and configuration HIGH/CRITICAL findings using the official Trivy container pinned by immutable digest (no third-party Trivy GitHub Action)\n\nNo release, visibility, licensing, or branch-protection changes.