Ci/gitleaks self hosted fix - #393
Merged
Merged
Conversation
hyperpolymath
enabled auto-merge (squash)
June 21, 2026 00:07
hyperpolymath
disabled auto-merge
June 21, 2026 00:08
This was referenced Jun 21, 2026
hyperpolymath
added a commit
that referenced
this pull request
Jun 24, 2026
#393 cut governance-reusable.yml from 9 jobs to 2; branch-protection still requires the named `governance / *` contexts -> estate-wide phantom deadlock. Restores the 8 governance jobs (recovered from 5a93d9d~1), keeps the newer staleness/hypatia jobs, bumps stale checkout pins to v7.0.0. actionlint clean (exit 0). Re-emitting these already-required contexts can only unblock compliant repos and surface genuine drift on non-compliant ones.
hyperpolymath
added a commit
that referenced
this pull request
Aug 26, 2026
… detection is currently OFF) (#642) ## What happened Commit `5a93d9d5` — PR #393, *"Ci/gitleaks self hosted fix"*, 2026-06-21 — deleted the SARIF output and its upload step from this workflow **as collateral of an unrelated gitleaks refactor**. 93 lines removed from this file, in a commit about something else. Since then Scorecard has emitted `results_format: json` only. JSON feeds the public OpenSSF API and the badge; **SARIF is what feeds GitHub code scanning.** So: - ✅ the badge kept updating — which is exactly why nobody noticed - ❌ the Security tab has heard nothing for **~3 months** ## Measured, 2026-08-25 | | | |---|---| | Scorecard alerts in this repo | **all 12 frozen** at commit `3e57141d`, `updated_at` **2026-06-03** | | Hypatia alerts, same repo, for contrast | updated **2026-08-24** | | `scorecard.yml` runs since | **succeeded** 08-07 and 08-09, produced nothing | A comment left behind in the file still claimed `security-events: write` *"uploads the SARIF"*. That has been false since June, and it is why the breakage looked like correct configuration. ## The part that actually matters The stale alerts are cosmetic. **The real cost is that a genuinely new regression in pinned-dependencies, token-permissions or SAST would raise no alert at all.** Detection is off, not just untidy. ## Why this doesn't cost you the badge `publish_results` is **independent of `results_format`** — it publishes to the OpenSSF API either way. Switching the format back to SARIF keeps the badge *and* restores code scanning. Both outputs are live with this shape. ## Sequencing note Merge this **before** dismissing the 12 stale alerts. Once SARIF flows again, Scorecard re-reports and GitHub **auto-closes** the ones that are genuinely fixed — and at least 6 of the 12 are (5 fixed in code, 1 pointing at a file the avow-protocol eviction deleted). Better to let the machine close them correctly than to hand-dismiss things that aren't false positives. ## Lockfile Added the `codeql-action` entry for this workflow. Without it the workflow dies at 0s — a separate estate fault this change must not walk into. ## Estate-wide Memory records **545 frozen Scorecard alerts gating 106 repos**. This fixes the source for `standards`; the same deletion likely needs reverting wherever the reusable was copied rather than called. **Not self-merging** — this restores a security-detection capability and is your call. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
hyperpolymath
added a commit
that referenced
this pull request
Sep 14, 2026
…781) ## The defect In `scorecard-reusable.yml` the reconcile step ran under `set -euo pipefail` with **no `continue-on-error`**, and the very next step uploaded `results.reconciled.sarif`. Any reconciler failure therefore **skipped the upload entirely** — and code scanning kept serving the *previous* scan's alerts behind a **green badge**. The repo looks scanned. It is not. Nothing in the run says otherwise. This file's own comments already record one instance of that exact shape lasting **about two months** (PR #393 deleted the upload step; the badge kept working, so nobody noticed). ## The fix Applied identically to both the `scorecard` and `pull-request` jobs: 1. **`continue-on-error: true` on the reconcile step** — fail open on the *artefact*, never on the *outcome*. 2. **A new `select-sarif` step** choosing `results.reconciled.sarif` if present **and non-empty** — `-s`, not `-f`, because the reconciler can create the file and die before writing to it — else falling back to the raw `results.sarif` with a `::warning` saying this upload is UNRECONCILED. **The upload is now unconditional.** 3. **A terminal `Fail if reconciliation did not succeed` step.** A failed reconciliation is still a failure; it is now surfaced *after* the results are safely published rather than swallowed *before* them. Guarded with `!cancelled()` so a cancelled run does not report as a reconciliation fault. The run still goes **red** when the reconciler breaks. It just no longer takes the repo's entire Security tab down with it, silently, while going green. ## Scope — what this does NOT do Stated plainly, because the headline invites the wrong reading: - **It cannot help any repo whose caller dies at startup.** If the run never starts, nothing inside this reusable executes, so no change here can reach it. Those repos need a caller-side repin; that is not this PR. - **It does not retroactively unfreeze anything.** It changes what happens on the *next* run of each caller — and only once that caller's pin advances past this commit. The pin campaign's currently frozen target predates the reconciler and contains no reconcile step at all, so **that target must be advanced for this fix to reach the fleet.** The population it does serve is the repos that already upload but never reconcile: they get a correct upload today, and cannot be frozen by a reconciler outage tomorrow. ## Verification | check | result | |---|---| | `actionlint` | exit 0 | | YAML parse | jobs `['scorecard','pull-request']`, 8 and 10 steps, ids `reconcile`/`select-sarif` in each | | `scripts/check-action-pins-resolve.sh` | **22/22** verifiable pins resolve | | select logic | exercised against reconciled-**present** / **absent** / **empty** — all three correct | The one unverified pin is an HTTP 301: `hyperpolymath/a2ml-ecosystem@f7a40a4d…`, the `a2ml` → `deed` rename redirect. Untouched here, under the standing hands-off ruling. `-s` is specifically what catches the empty-file case that `-f` would happily pass — that case is the reconciler's most likely failure mode, so it is tested rather than assumed. Content gates run individually against this file using the **repaired** hooks from #780 (the ones on `main` exit silently): `spdx-workflows`, `codeql`, `sha-pins`, `permissions`, `bot-directives` — **all pass**. ## Disclosure: `--no-verify` on both commit and push Two distinct reasons, both unrelated to this file: 1. **Registry drift inherited from `main`** — three `source_hash` lines in `.machine_readable/REGISTRY.a2ml`. Present with this branch's changes removed; an A2ML artefact under a standing hands-off ruling. 2. **The pre-push gate itself is broken** — and this branch is a clean natural experiment for #780. The push died at `Running Workflow SPDX...` with **no further output**: the silent-death signature. The branch in #780, which carries the repair, pushed through the identical hook minutes earlier without complaint. Same repo, same hook path, fix present vs absent, opposite outcomes. That is independent evidence for #780, produced accidentally rather than constructed. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_0168Bgpez8mFBcAqYAj8VgEx
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.