You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Carry the current immutable Scorecard SARIF uploader on protected Wardnet ancestry without importing stale workflow ownership, while keeping the local Scorecard evidence contract explicit.
Protected/default main is f8260f1e03836039ff9463dd99fa982e4e270c4b. Fresh upstream inventory on 2026-09-24 verifies immutable github/codeql-action release v4.38.2, published 2026-09-24T10:27:53Z, whose annotated tag resolves to commit 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2. v4.38.2 updates the default CodeQL bundle to 2.27.1.
Current exact head is 077fd4679093d57e6b7f18cc3a00353734cfffc3. The protected-main-relative delta remains intentionally narrow:
.github/workflows/scorecard-analysis.yml: upload-sarif moves from protected v4.37.7 ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd to immutable v4.38.2 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2;
tests/workflow_queue_contract.rs: retain the supported non-PR Scorecard event contract and explicitly require security-events: write.
Runner, default-branch triggers, checkout pin, Scorecard pin, SARIF path, permissions boundary and runtime behavior are otherwise unchanged.
Concurrent dependency lanes / single writer
Dependabot #451 opened on 2026-09-24 for v4.38.1 while upstream v4.38.2 was already present in the same generated changelog and became an immutable release minutes earlier. #174 remains the established sole writer for the local Scorecard workflow and now carries the complete dependency update past #451. Do not race a second workflow writer or close#451 merely because this commit exists; first verify this unchanged exact successor head and the complete delta. #141 remains older predecessor evidence under the same rule.
Issue #362 identified the GHAS PR comparison warning for the local Scorecard configuration. The bounded same-repository pull_request experiment executed but did not restore configuration identity, so that trigger was normally reverted. No pull_request_target, permission broadening, no-op redispatch commit, or gate weakening is retained. #362 remains open for a GitHub/Scorecard-supported configuration-identity solution.
Exact-head integration gate
Every predecessor result is historical after the v4.38.2 source movement. Keep Draft until this unchanged exact head has fresh protected-base compatibility, zero valid unresolved findings/threads, an accepted independent approval path, and every then-live deterministic/security/SAST/CodeQL/coverage/package/SBOM/provenance/governance requirement is terminal-valid.
Central delegated-verdict ownership remains .github#1929; generic solo-maintainer approval governance remains .github#772. Wardnet does not copy those controls, self/model approve, weaken gates, force push/destructively rebase, promote predecessor evidence, use a mutable foreign dependency, or use routine administrator bypass.
seonghobae
changed the title
build(deps): bump CodeQL SARIF uploader to 4.37.9 on current main
build(deps): bump CodeQL SARIF uploader to 4.38.0 on current main
Sep 12, 2026
Fresh owner handoff: #362 records a newly reproduced Wardnet-local Scorecard observability defect. On exact PR #361 head c6d3fd45eba1aceef074cc8b9934937f67b1d41a, GitHub Advanced Security Scorecard check 103545605700 is neutral with 1 configuration not found for scorecard-analysis.yml / supply-chain/branch-protection. Root cause is the protected workflow's default-branch-only trigger set: main has the SARIF configuration, while PR heads normally have no matching Scorecard analysis for GitHub comparison. Upstream OpenSSF currently treats pull_request as experimental and does not support fork repos, so do not blindly add a privileged PR trigger or remove SARIF to silence the warning. #174 remains the sole workflow writer; use #362's RED/GREEN acceptance here or in a verified complete successor. No competing workflow branch created.
seonghobae
changed the title
build(deps): bump CodeQL SARIF uploader to 4.38.0 on current main
build(scorecard): bump SARIF uploader to 4.38.0 on current main
Sep 12, 2026
seonghobae
changed the title
build(scorecard): bump SARIF uploader to 4.38.0 on current main
build(scorecard): bump SARIF uploader to 4.38.2 on current main
Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Carry the current immutable Scorecard SARIF uploader on protected Wardnet ancestry without importing stale workflow ownership, while keeping the local Scorecard evidence contract explicit.
Protected/default
mainisf8260f1e03836039ff9463dd99fa982e4e270c4b. Fresh upstream inventory on 2026-09-24 verifies immutablegithub/codeql-actionreleasev4.38.2, published 2026-09-24T10:27:53Z, whose annotated tag resolves to commit2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2. v4.38.2 updates the default CodeQL bundle to 2.27.1.Current exact head is
077fd4679093d57e6b7f18cc3a00353734cfffc3. The protected-main-relative delta remains intentionally narrow:.github/workflows/scorecard-analysis.yml:upload-sarifmoves from protected v4.37.7ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0ddto immutable v4.38.22892aa5e19bbd11bc0cff5427e3b750a04d9e3c2;tests/workflow_queue_contract.rs: retain the supported non-PR Scorecard event contract and explicitly requiresecurity-events: write.Runner, default-branch triggers, checkout pin, Scorecard pin, SARIF path, permissions boundary and runtime behavior are otherwise unchanged.
Concurrent dependency lanes / single writer
Dependabot #451 opened on 2026-09-24 for v4.38.1 while upstream v4.38.2 was already present in the same generated changelog and became an immutable release minutes earlier. #174 remains the established sole writer for the local Scorecard workflow and now carries the complete dependency update past #451. Do not race a second workflow writer or close #451 merely because this commit exists; first verify this unchanged exact successor head and the complete delta. #141 remains older predecessor evidence under the same rule.
#362 experiment and repair
Issue #362 identified the GHAS PR comparison warning for the local Scorecard configuration. The bounded same-repository
pull_requestexperiment executed but did not restore configuration identity, so that trigger was normally reverted. Nopull_request_target, permission broadening, no-op redispatch commit, or gate weakening is retained. #362 remains open for a GitHub/Scorecard-supported configuration-identity solution.Exact-head integration gate
Every predecessor result is historical after the v4.38.2 source movement. Keep Draft until this unchanged exact head has fresh protected-base compatibility, zero valid unresolved findings/threads, an accepted independent approval path, and every then-live deterministic/security/SAST/CodeQL/coverage/package/SBOM/provenance/governance requirement is terminal-valid.
Central delegated-verdict ownership remains
.github#1929; generic solo-maintainer approval governance remains.github#772. Wardnet does not copy those controls, self/model approve, weaken gates, force push/destructively rebase, promote predecessor evidence, use a mutable foreign dependency, or use routine administrator bypass.