Skip to content

build(scorecard): bump SARIF uploader to 4.38.2 on current main - #174

Draft
seonghobae wants to merge 6 commits into
mainfrom
build/codeql-upload-sarif-4.37.9-main
Draft

seonghobae wants to merge 6 commits into
mainfrom
build/codeql-upload-sarif-4.37.9-main

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 6, 2026 •

Copy link
Copy Markdown
Contributor

Purpose

Carry the current immutable Scorecard SARIF uploader on protected Wardnet ancestry without importing stale workflow ownership, while keeping the local Scorecard evidence contract explicit.

Protected/default main is f8260f1e03836039ff9463dd99fa982e4e270c4b. Fresh upstream inventory on 2026-09-24 verifies immutable github/codeql-action release v4.38.2, published 2026-09-24T10:27:53Z, whose annotated tag resolves to commit 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2. v4.38.2 updates the default CodeQL bundle to 2.27.1.

Current exact head is 077fd4679093d57e6b7f18cc3a00353734cfffc3. The protected-main-relative delta remains intentionally narrow:

  • .github/workflows/scorecard-analysis.yml: upload-sarif moves from protected v4.37.7 ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd to immutable v4.38.2 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2;
  • tests/workflow_queue_contract.rs: retain the supported non-PR Scorecard event contract and explicitly require security-events: write.

Runner, default-branch triggers, checkout pin, Scorecard pin, SARIF path, permissions boundary and runtime behavior are otherwise unchanged.

Concurrent dependency lanes / single writer

Dependabot #451 opened on 2026-09-24 for v4.38.1 while upstream v4.38.2 was already present in the same generated changelog and became an immutable release minutes earlier. #174 remains the established sole writer for the local Scorecard workflow and now carries the complete dependency update past #451. Do not race a second workflow writer or close #451 merely because this commit exists; first verify this unchanged exact successor head and the complete delta. #141 remains older predecessor evidence under the same rule.

#362 experiment and repair

Issue #362 identified the GHAS PR comparison warning for the local Scorecard configuration. The bounded same-repository pull_request experiment executed but did not restore configuration identity, so that trigger was normally reverted. No pull_request_target, permission broadening, no-op redispatch commit, or gate weakening is retained. #362 remains open for a GitHub/Scorecard-supported configuration-identity solution.

Exact-head integration gate

Every predecessor result is historical after the v4.38.2 source movement. Keep Draft until this unchanged exact head has fresh protected-base compatibility, zero valid unresolved findings/threads, an accepted independent approval path, and every then-live deterministic/security/SAST/CodeQL/coverage/package/SBOM/provenance/governance requirement is terminal-valid.

Central delegated-verdict ownership remains .github#1929; generic solo-maintainer approval governance remains .github#772. Wardnet does not copy those controls, self/model approve, weaken gates, force push/destructively rebase, promote predecessor evidence, use a mutable foreign dependency, or use routine administrator bypass.

@coderabbitai

coderabbitai Bot commented Sep 6, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae added priority: medium Normal-priority or P2 work status: draft type: maintenance Maintenance, build, dependency, or operational upkeep maintenance labels Sep 7, 2026 — with ChatGPT Codex Connector
@seonghobae seonghobae changed the title build(deps): bump CodeQL SARIF uploader to 4.37.9 on current main build(deps): bump CodeQL SARIF uploader to 4.38.0 on current main Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

Fresh owner handoff: #362 records a newly reproduced Wardnet-local Scorecard observability defect. On exact PR #361 head c6d3fd45eba1aceef074cc8b9934937f67b1d41a, GitHub Advanced Security Scorecard check 103545605700 is neutral with 1 configuration not found for scorecard-analysis.yml / supply-chain/branch-protection. Root cause is the protected workflow's default-branch-only trigger set: main has the SARIF configuration, while PR heads normally have no matching Scorecard analysis for GitHub comparison. Upstream OpenSSF currently treats pull_request as experimental and does not support fork repos, so do not blindly add a privileged PR trigger or remove SARIF to silence the warning. #174 remains the sole workflow writer; use #362's RED/GREEN acceptance here or in a verified complete successor. No competing workflow branch created.

@seonghobae seonghobae changed the title build(deps): bump CodeQL SARIF uploader to 4.38.0 on current main build(scorecard): bump SARIF uploader to 4.38.0 on current main Sep 12, 2026
@seonghobae seonghobae changed the title build(scorecard): bump SARIF uploader to 4.38.0 on current main build(scorecard): bump SARIF uploader to 4.38.2 on current main Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance priority: medium Normal-priority or P2 work status: draft type: maintenance Maintenance, build, dependency, or operational upkeep

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant