Skip to content

Ci/gitleaks self hosted fix - #393

Merged
hyperpolymath merged 4 commits into
mainfrom
ci/gitleaks-self-hosted-fix
Jun 21, 2026
Merged

hyperpolymath merged 4 commits into
mainfrom
ci/gitleaks-self-hosted-fix

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

No description provided.

@hyperpolymath
hyperpolymath enabled auto-merge (squash) June 21, 2026 00:07
@hyperpolymath
hyperpolymath disabled auto-merge June 21, 2026 00:08
@hyperpolymath
hyperpolymath merged commit 5a93d9d into main Jun 21, 2026
12 of 14 checks passed
@hyperpolymath
hyperpolymath deleted the ci/gitleaks-self-hosted-fix branch June 21, 2026 00:09
hyperpolymath added a commit that referenced this pull request Jun 24, 2026
#393 cut governance-reusable.yml from 9 jobs to 2; branch-protection
still requires the named `governance / *` contexts -> estate-wide
phantom deadlock. Restores the 8 governance jobs (recovered from
5a93d9d~1), keeps the newer staleness/hypatia jobs, bumps stale checkout
pins to v7.0.0. actionlint clean (exit 0). Re-emitting these
already-required contexts can only unblock compliant repos and surface
genuine drift on non-compliant ones.
hyperpolymath added a commit that referenced this pull request Aug 26, 2026
… detection is currently OFF) (#642)

## What happened

Commit `5a93d9d5` — PR #393, *"Ci/gitleaks self hosted fix"*, 2026-06-21
— deleted the SARIF output and its upload step from this workflow **as
collateral of an unrelated gitleaks refactor**. 93 lines removed from
this file, in a commit about something else.

Since then Scorecard has emitted `results_format: json` only. JSON feeds
the public OpenSSF API and the badge; **SARIF is what feeds GitHub code
scanning.** So:

- ✅ the badge kept updating — which is exactly why nobody noticed
- ❌ the Security tab has heard nothing for **~3 months**

## Measured, 2026-08-25

| | |
|---|---|
| Scorecard alerts in this repo | **all 12 frozen** at commit
`3e57141d`, `updated_at` **2026-06-03** |
| Hypatia alerts, same repo, for contrast | updated **2026-08-24** |
| `scorecard.yml` runs since | **succeeded** 08-07 and 08-09, produced
nothing |

A comment left behind in the file still claimed `security-events: write`
*"uploads the SARIF"*. That has been false since June, and it is why the
breakage looked like correct configuration.

## The part that actually matters

The stale alerts are cosmetic. **The real cost is that a genuinely new
regression in pinned-dependencies, token-permissions or SAST would raise
no alert at all.** Detection is off, not just untidy.

## Why this doesn't cost you the badge

`publish_results` is **independent of `results_format`** — it publishes
to the OpenSSF API either way. Switching the format back to SARIF keeps
the badge *and* restores code scanning. Both outputs are live with this
shape.

## Sequencing note

Merge this **before** dismissing the 12 stale alerts. Once SARIF flows
again, Scorecard re-reports and GitHub **auto-closes** the ones that are
genuinely fixed — and at least 6 of the 12 are (5 fixed in code, 1
pointing at a file the avow-protocol eviction deleted). Better to let
the machine close them correctly than to hand-dismiss things that aren't
false positives.

## Lockfile

Added the `codeql-action` entry for this workflow. Without it the
workflow dies at 0s — a separate estate fault this change must not walk
into.

## Estate-wide

Memory records **545 frozen Scorecard alerts gating 106 repos**. This
fixes the source for `standards`; the same deletion likely needs
reverting wherever the reusable was copied rather than called.

**Not self-merging** — this restores a security-detection capability and
is your call.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
hyperpolymath added a commit that referenced this pull request Sep 14, 2026
…781)

## The defect

In `scorecard-reusable.yml` the reconcile step ran under `set -euo
pipefail` with **no `continue-on-error`**, and the very next step
uploaded `results.reconciled.sarif`.

Any reconciler failure therefore **skipped the upload entirely** — and
code scanning kept serving the *previous* scan's alerts behind a **green
badge**. The repo looks scanned. It is not. Nothing in the run says
otherwise.

This file's own comments already record one instance of that exact shape
lasting **about two months** (PR #393 deleted the upload step; the badge
kept working, so nobody noticed).

## The fix

Applied identically to both the `scorecard` and `pull-request` jobs:

1. **`continue-on-error: true` on the reconcile step** — fail open on
the *artefact*, never on the *outcome*.
2. **A new `select-sarif` step** choosing `results.reconciled.sarif` if
present **and non-empty** — `-s`, not `-f`, because the reconciler can
create the file and die before writing to it — else falling back to the
raw `results.sarif` with a `::warning` saying this upload is
UNRECONCILED. **The upload is now unconditional.**
3. **A terminal `Fail if reconciliation did not succeed` step.** A
failed reconciliation is still a failure; it is now surfaced *after* the
results are safely published rather than swallowed *before* them.
Guarded with `!cancelled()` so a cancelled run does not report as a
reconciliation fault.

The run still goes **red** when the reconciler breaks. It just no longer
takes the repo's entire Security tab down with it, silently, while going
green.

## Scope — what this does NOT do

Stated plainly, because the headline invites the wrong reading:

- **It cannot help any repo whose caller dies at startup.** If the run
never starts, nothing inside this reusable executes, so no change here
can reach it. Those repos need a caller-side repin; that is not this PR.
- **It does not retroactively unfreeze anything.** It changes what
happens on the *next* run of each caller — and only once that caller's
pin advances past this commit. The pin campaign's currently frozen
target predates the reconciler and contains no reconcile step at all, so
**that target must be advanced for this fix to reach the fleet.**

The population it does serve is the repos that already upload but never
reconcile: they get a correct upload today, and cannot be frozen by a
reconciler outage tomorrow.

## Verification

| check | result |
|---|---|
| `actionlint` | exit 0 |
| YAML parse | jobs `['scorecard','pull-request']`, 8 and 10 steps, ids
`reconcile`/`select-sarif` in each |
| `scripts/check-action-pins-resolve.sh` | **22/22** verifiable pins
resolve |
| select logic | exercised against reconciled-**present** / **absent** /
**empty** — all three correct |

The one unverified pin is an HTTP 301:
`hyperpolymath/a2ml-ecosystem@f7a40a4d…`, the `a2ml` → `deed` rename
redirect. Untouched here, under the standing hands-off ruling.

`-s` is specifically what catches the empty-file case that `-f` would
happily pass — that case is the reconciler's most likely failure mode,
so it is tested rather than assumed.

Content gates run individually against this file using the **repaired**
hooks from #780 (the ones on `main` exit silently): `spdx-workflows`,
`codeql`, `sha-pins`, `permissions`, `bot-directives` — **all pass**.

## Disclosure: `--no-verify` on both commit and push

Two distinct reasons, both unrelated to this file:

1. **Registry drift inherited from `main`** — three `source_hash` lines
in `.machine_readable/REGISTRY.a2ml`. Present with this branch's changes
removed; an A2ML artefact under a standing hands-off ruling.
2. **The pre-push gate itself is broken** — and this branch is a clean
natural experiment for #780. The push died at `Running Workflow SPDX...`
with **no further output**: the silent-death signature. The branch in
#780, which carries the repair, pushed through the identical hook
minutes earlier without complaint. Same repo, same hook path, fix
present vs absent, opposite outcomes.

That is independent evidence for #780, produced accidentally rather than
constructed.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_0168Bgpez8mFBcAqYAj8VgEx
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant