Skip to content

ci: complete Wave 4 security migration - #81

Merged
AviBackToBlack merged 1 commit into
mainfrom
chore/github-governance-wave4-security
Sep 12, 2026
Merged

AviBackToBlack merged 1 commit into
mainfrom
chore/github-governance-wave4-security

Conversation

@AviBackToBlack

@AviBackToBlack AviBackToBlack commented Sep 12, 2026 •

Copy link
Copy Markdown
Owner

Completes the Wave 4 security-engine migration for this repository:\n\n- add weekly advisory OpenSSF Scorecard with full-SHA-pinned actions and SARIF upload\n- keep Scorecard results private to GitHub Code Scanning (publish_results: false)\n- remove the now-disabled Advanced CodeQL workflow after successful migration to GitHub CodeQL Default Setup\n- add advisory Trivy filesystem scanning for dependency and configuration HIGH/CRITICAL findings using the official Trivy container pinned by immutable digest (no third-party Trivy GitHub Action)\n\nNo release, visibility, licensing, or branch-protection changes.


Devin Review

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 2 potential issues.

Devin Review


jobs:
analyze:
name: Analyze (${{ matrix.language }})

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Required CodeQL checks disappear

Deleting CodeQL Advanced removes the three Analyze (...) checks still required by the main-branch ruleset. Default Setup reports CodeQL, so future pull requests cannot satisfy the ruleset or merge.

Learn more

The repository ruleset currently requires Analyze (python), Analyze (javascript-typescript), and Analyze (actions). Those contexts come from this workflow's matrix job. GitHub CodeQL Default Setup produces a single CodeQL check instead, so deleting the workflow does not migrate the required status checks.

Example: After this PR merges, a new pull request receives a successful CodeQL result. The ruleset still waits indefinitely for all three Analyze (...) results, which no active workflow can create.

Recommended fix: Update the main-branch ruleset to require the Default Setup CodeQL context before deleting this workflow. Keep the old workflow active until that external migration is complete if the ruleset cannot be changed atomically.

Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines -1 to -7
name: "CodeQL Advanced"

on:
push:
branches: ["main"]
pull_request:
branches: ["main"]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Security documentation remains stale

The living security guides still reference this deleted workflow and omit Scorecard, Trivy, and CodeQL Default Setup. Update the documented scan inventory and triggers.

Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

@AviBackToBlack
AviBackToBlack merged commit 9941636 into main Sep 12, 2026
11 checks passed
@AviBackToBlack
AviBackToBlack deleted the chore/github-governance-wave4-security branch September 12, 2026 01:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants