Repository navigation
ci: remove per-repo Semgrep scan (the Semgrep Code app covers PRs) - #167
Conversation
The semgrep-code-hyperpolymath GitHub App (Semgrep Managed Scans) already reports semgrep-cloud-platform/scan on every pull request here, so this workflow scanned the same code twice. No Semgrep context is required by any ruleset. actions.lock loses only the Semgrep-specific entries. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013aSu89DNALjTYHBvA6FcoM
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
💤 Files with no reviewable changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (11)
|
| Layer / File(s) | Summary |
|---|---|
Remove the Semgrep workflow .github/workflows/semgrep.yml |
The workflow and its triggers, Semgrep scan job, and SARIF upload step were removed. |
Priority: ⬇️ Low
Estimated code review effort: 2 (Simple) | ~5 minutes
Change: Other
Merge Risk: 🔵 Low · up to 6d996
Pull requests retain the reported Semgrep app scan, but default-branch and scheduled Semgrep coverage now depends on an unverified Cloud schedule. The change is mergeable with owner awareness of that gap.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
| Check name | Status | Explanation |
|---|---|---|
| Title check | ✅ Passed | The title clearly and concisely describes the main change: removing the repository-level Semgrep scan because the Semgrep Code app covers pull requests. |
| Description check | ✅ Passed | The description directly explains the removal of the duplicate Semgrep workflow, the coverage change, verification performed, and the CI scope. |
| Docstring Coverage | ✅ Passed | No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0… |
| Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
✨ Finishing Touches
🛠️ Fix failing CI checks
- Commit to this branch
- Create a new PR
- Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
A rabbit checked the workflow file,
Then found the scan had left the trail.
No SARIF hopped into the queue,
The empty schedule vanished too,
And clover grew where jobs once ran.
Comment @coderabbitai help to get the list of available commands.
|
|
Add Carrot credits or activate Agent usage billing to use Autopilot |
|
The CI failures may require manual intervention. View agent analysis |



Summary
Removes this repo's own Semgrep scan. The
semgrep-code-hyperpolymathGitHub App (Semgrep Managed Scans) already reportssemgrep-cloud-platform/scanon every pull request here, so PRs were scanned twice. No ruleset requires a Semgrep context in this repo (checked viarules/branches/main).No issue. This is owner-requested estate cleanup (duplicate Semgrep scanning).
Type of change
📌 New pins
Head SHA:
6d99697ef2c3b4544e5b18b9d4b847e150a32c13. No pins added or changed.github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2How has this been verified?
Files:
M .github/workflows/actions.lock
D .github/workflows/semgrep.yml
actions.lock: only the Semgrep-specific entries removed (thesemgrep.ymlworkflow key and/or thereturntocorp/semgrep-actionlist item and its dependency block). Every other entry, transitive dependencies included, is untouched.gh actions-lock --no-fix --json: findings diffed before/after. 0 new findings; only findings that belonged to the removed Semgrep entries disappeared.yq -e .parses every changed YAML file.Checklist
git commit -S, verifiedG).Notes for reviewers
Coverage change, stated rather than hidden: the removed workflow also ran on
pushandschedule. The app reports only on pull requests: nosemgrep-cloud-platform/scancheck exists onmainHEADc420875. Default-branch and scheduled full scans now depend on Semgrep Cloud's own schedule, which is not verified from GitHub.After merge the
SEMGREP_APP_TOKENrepo secret is unused; the owner approved deleting it then. Audit prose that listssemgrep.ymlis not edited here.🤖 Generated with Claude Code
https://claude.ai/code/session_013aSu89DNALjTYHBvA6FcoM