Skip to content

ci: remove per-repo Semgrep scan (the Semgrep Code app covers PRs) - #167

Merged
hyperpolymath merged 1 commit into
mainfrom
chore/drop-duplicate-semgrep
Oct 8, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
chore/drop-duplicate-semgrep

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Removes this repo's own Semgrep scan. The semgrep-code-hyperpolymath GitHub App (Semgrep Managed Scans) already reports semgrep-cloud-platform/scan on every pull request here, so PRs were scanned twice. No ruleset requires a Semgrep context in this repo (checked via rules/branches/main).

No issue. This is owner-requested estate cleanup (duplicate Semgrep scanning).

Type of change

  • 🐛 Bug fix: n/a
  • ✨ New feature: n/a
  • 💥 Breaking change: no. No required check is removed.
  • 🕳️ Soundness fix: n/a
  • 📖 Documentation: n/a
  • 🧹 Refactor / tech debt: n/a
  • ⚡ Performance: n/a
  • 🔧 Build / CI / tooling

📌 New pins

Head SHA: 6d99697ef2c3b4544e5b18b9d4b847e150a32c13. No pins added or changed.

  • removed: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2

How has this been verified?

Files:
M .github/workflows/actions.lock
D .github/workflows/semgrep.yml

actions.lock: only the Semgrep-specific entries removed (the semgrep.yml workflow key and/or the returntocorp/semgrep-action list item and its dependency block). Every other entry, transitive dependencies included, is untouched.

  • gh actions-lock --no-fix --json: findings diffed before/after. 0 new findings; only findings that belonged to the removed Semgrep entries disappeared.
  • yq -e . parses every changed YAML file.

Checklist

  • My commits are signed (git commit -S, verified G).
  • I ran the project's own checks/tests locally and they pass: the workflow checks above. The change is CI-only, so no build or test was affected.
  • New files carry the correct SPDX identifier: n/a, no new files.
  • Docs are updated: see notes. Prose that mentions Semgrep is left as is.
  • I have not introduced a soundness hole. The coverage change is flagged below.

Notes for reviewers

Coverage change, stated rather than hidden: the removed workflow also ran on push and schedule. The app reports only on pull requests: no semgrep-cloud-platform/scan check exists on main HEAD c420875. Default-branch and scheduled full scans now depend on Semgrep Cloud's own schedule, which is not verified from GitHub.
After merge the SEMGREP_APP_TOKEN repo secret is unused; the owner approved deleting it then. Audit prose that lists semgrep.yml is not edited here.

🤖 Generated with Claude Code

https://claude.ai/code/session_013aSu89DNALjTYHBvA6FcoM

The semgrep-code-hyperpolymath GitHub App (Semgrep Managed Scans) already
reports semgrep-cloud-platform/scan on every pull request here, so this
workflow scanned the same code twice. No Semgrep context is required by
any ruleset. actions.lock loses only the Semgrep-specific entries.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013aSu89DNALjTYHBvA6FcoM
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: b3c71370-fe48-4575-b20d-7e26cd656a9b
📥 Commits

Reviewing files that changed from the base of the PR and between c420875 and 6d99697.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (1)
  • .github/workflows/semgrep.yml
💤 Files with no reviewable changes (1)
  • .github/workflows/semgrep.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (11)
  • GitHub Check: GitGuardian Security Checks
  • GitHub Check: scan / rust-secrets
  • GitHub Check: scan / shell-secrets
  • GitHub Check: scan / gitleaks
  • GitHub Check: Groove manifest check
  • GitHub Check: Validate K9 contracts
  • GitHub Check: Language registry consistency
  • GitHub Check: Validate DEED manifests
  • GitHub Check: lint-workflows
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: lint-workflows
⚠️ CI failures not shown inline (2)

GitHub Actions: Workflow Security Linter / 0_lint-workflows.txt: ci: remove per-repo Semgrep scan (the Semgrep Code app covers PRs)

Conclusion: failure

View job details

##[group]Run gh actions-lock --verify-local
 �[36;1mgh actions-lock --verify-local�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ! STALE github/codeql-action@1c5b675653bb5c22dbe9b12b556ec555138e09fd
   lockfile pins github/codeql-action@1c5b675653bb5c22dbe9b12b556ec555138e09fd but no uses: in this workflow references it
 1 of 15 workflows failed: 1 stale
 11 actions are pinned to a bare SHA without a tag ref
 ↳ run `gh actions-lock` to pin to tagged releases
 Run without --verify-local to resolve and pin missing actions.
 ##[error]Process completed with exit code 1.

GitHub Actions: Workflow Security Linter / lint-workflows: ci: remove per-repo Semgrep scan (the Semgrep Code app covers PRs)

Conclusion: failure

View job details

##[group]Run gh actions-lock --verify-local
 �[36;1mgh actions-lock --verify-local�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ! STALE github/codeql-action@1c5b675653bb5c22dbe9b12b556ec555138e09fd
   lockfile pins github/codeql-action@1c5b675653bb5c22dbe9b12b556ec555138e09fd but no uses: in this workflow references it
 1 of 15 workflows failed: 1 stale
 11 actions are pinned to a bare SHA without a tag ref
 ↳ run `gh actions-lock` to pin to tagged releases
 Run without --verify-local to resolve and pin missing actions.
 ##[error]Process completed with exit code 1.

📝 Summary

Summary by CodeRabbit

  • Chores
    • Automated security scans no longer run on code changes, on a weekly schedule, or on demand. Scan results are no longer uploaded to GitHub. This change affects the project’s development and review process; it does not describe a change to the app’s user-facing features.

Walkthrough

The Semgrep GitHub Actions workflow was removed. This includes its triggers, scan job, and SARIF upload step.

Changes

Semgrep workflow

Layer / File(s) Summary
Remove the Semgrep workflow
.github/workflows/semgrep.yml
The workflow and its triggers, Semgrep scan job, and SARIF upload step were removed.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~5 minutes

Change: Other

Merge Risk: 🔵 Low · up to 6d996

Pull requests retain the reported Semgrep app scan, but default-branch and scheduled Semgrep coverage now depends on an unverified Cloud schedule. The change is mergeable with owner awareness of that gap.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: removing the repository-level Semgrep scan because the Semgrep Code app covers pull requests.
Description check ✅ Passed The description directly explains the removal of the duplicate Semgrep workflow, the coverage change, verification performed, and the CI scope.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🛠️ Fix failing CI checks
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checked the workflow file,
Then found the scan had left the trail.
No SARIF hopped into the queue,
The empty schedule vanished too,
And clover grew where jobs once ran.

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 8, 2026

Copy link
Copy Markdown

@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Add Carrot credits or activate Agent usage billing to use Autopilot

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Agent ran but produced no code changes.

The CI failures may require manual intervention.

View agent analysis
I haven't changed any files. The only possible fixes are an edit to a CI workflow or a lockfile, and I'm not allowed to touch either.

**Why the check fails:** `gh actions-lock --verify-local` reports that `codeql.yml` doesn't match the lockfile:
- `.github/workflows/codeql.yml:43` and `:49` use `github/codeql-action/{init,analyze}@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2` (v4.38.2).
- `.github/workflows/actions.lock:17` still pins `github/codeql-action@1c5b675653bb5c22dbe9b12b556ec555138e09fd` (v4.38.1) for `codeql.yml`, with its dependency block at lines 72–76.

So the lock entry for `codeql.yml` is stale: it points at a commit no workflow uses any more.

**Probably a side effect of this PR:** the head commit has no diff against `origin/main`, so the PR's content is already on main. The PR description says the lock entry for `codeql-action@2892aa5` came from `semgrep.yml`'s `upload-sarif` step. That suggests the 2892aa5 dependency block used to be supplied by the Semgrep entry, and removing it exposed the out-of-date `codeql.yml` pin. That's my reading of the PR text; I haven't checked it against the lockfile history.

**Fix (needs someone who can change CI files):** either of these works.
1. **Recommended:** run `gh actions-lock` to regenerate the lockfile. It should repin `codeql.yml` to `github/codeql-action@2892aa5…` (v4.38.2) and add that dependency block in place of the `1c5b675…` one.
2. Change `codeql.yml` back to `@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1`. This would undo a deliberate version bump, so I wouldn't do it.

@hyperpolymath
hyperpolymath merged commit 9fcab1b into main Oct 8, 2026
15 of 18 checks passed
@hyperpolymath
hyperpolymath deleted the chore/drop-duplicate-semgrep branch October 8, 2026 11:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant