chore: cut code-scanning alerts on main (#231) - #235
Merged
Merged
Conversation
Drops the code-scanning alert backlog on `main` from 248 to a floor of config-only Scorecard leftovers, matching the noise-floor approach the fleet-wide pilot proved in Extensions-Logging-Data. InspectCode (222 → expected ~0) - AuditTrail.slnx.DotSettings suppresses the eight rules that account for all 222 findings and are either analyzer noise (RedundantUsingDirective, RedundantNameQualifier, RedundantSuppressNullableWarningExpression), the library-defensive-null-check false positives (Condition/NullCoalescing… APIContract), the flat-root-namespace false positive (CheckNamespace), or the public-API "unused" false positives (UnusedAutoPropertyAccessor and NotAccessedPositionalProperty, .Global variants). - Real S8969 findings addressed by removing redundant `!` after Assert.NotNull / flow-narrowed nullable checks in DbContextItemBag, AuditSchemaInstaller, and three test files. - Real Unused/Redundant findings addressed: `context` renamed to `_` in two IHostBuilder lambdas; single-arg `IModelCacheKeyFactory.Create` overload removed (not part of the current interface); explicit type arguments dropped from two invocations. Test entity POCOs get scoped `// ReSharper disable UnusedAutoPropertyAccessor.Local` blocks since EF hydrates them via reflection. zizmor (10 → 0) - template-injection (5): pr.yaml codeql step and release.yaml NUGET_USER check bind context values through env vars. - dependabot-cooldown (2): 7-day cooldown added to both ecosystems. - artipacked (1): integration.yaml checkout gets persist-credentials: false. - superfluous-actions (1): release.yaml attach step swaps softprops/action-gh-release for `gh release upload` (release already exists — workflow only runs on release:published). - dangerous-triggers (1): `pull_request_target` on pr.yaml waived via new zizmor.yml with a documented rationale — migration to `pull_request` is a workflow-wide refactor tracked separately. Scorecard (16, already below the <25 bar) - DangerousWorkflowID x7 all trace to the same `pull_request_target` + refs/pull/… checkout pattern — resolved by the same follow-up. - PinnedDependenciesID x5 are `dotnet restore` calls; requires NuGet lockfiles (has known ETL-family gh-pages interaction — defer). - Config-only findings (SASTID, CodeReviewID, CIIBestPracticesID, BranchProtectionID) left as-is. Closes #231 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This was referenced Aug 20, 2026
Chris-Wolfgang
added a commit
that referenced
this pull request
Aug 21, 2026
…ty.yaml I split zizmor.yml onto the wrong side in #235 — workflow-security.yaml here now passes --config zizmor.yml, but without the file being present on this branch the zizmor job fails "config file not found". Moves zizmor.yml onto this branch so the two land together. The dangerous-triggers waiver on pr.yaml is the whole reason both files are needed at once — without the config, zizmor reports the finding again and gates the job. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Chris-Wolfgang
added a commit
that referenced
this pull request
Aug 22, 2026
…-231-workflows chore: workflow security tightening (protected-file split of #235)
…Contain (MA0002) Stage 2 on #235 caught seven new MA0002 errors after #234 bumped Meziantou.Analyzer 3.0.142 → 3.0.164. The newer analyzer flags xunit Assert.Contains / DoesNotContain over IEnumerable<string> and Assert.NotEqual over two strings as needing an explicit IEqualityComparer<string>, per the rule's `use-comparer-that-controls-equality` guidance. Pass StringComparer.Ordinal to each flagged call — matches how xunit already resolves the parameterless overload for strings (ordinal via generic Equals), so no behavior change: - AuditCaptureBranchTests.cs:93,94 - AuditingDbContextSaveChangesTests.cs:32 - PipeDelimitedEntityKeySerializerTests.cs:34,64,82,83 All 22 affected tests still pass on net10.0 locally. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Drops the code-scanning alert backlog on
mainfrom 248 to a floor of config-only Scorecard leftovers, matching the noise-floor approach the fleet-wide pilot proved in Extensions-Logging-Data (repo-template#431).Closes #231.
InspectCode: 222 → ~0
Two moves:
AuditTrail.slnx.DotSettings(new) suppresses the eight R# rules that account for every one of the 222 findings and are either analyzer noise (already covered by the Roslyn stack) or fleet-shape false positives — mirrors the canonical profile from Extensions-Logging-Data:CheckNamespaceWolfgang.AuditTrail.*namespace across all packages, independent of package folder. Polyfills sit underSystem.*on purpose.RedundantUsingDirective<ImplicitUsings>gated on TFM; explicitSystem.*usings are required onnetstandard2.0/net6.0but look redundant onnet10.0.RedundantNameQualifierRedundantSuppressNullableWarningExpressionS8969is the rule we actually gate on — see below.ConditionIsAlwaysTrueOrFalseAccordingToNullableAPIContractNullCoalescingConditionIsAlwaysNotNullAccordingToAPIContractUnusedAutoPropertyAccessor.GlobalNotAccessedPositionalProperty.GlobalActual defects fixed (not suppressed):
!afterAssert.NotNull/ flow-narrowedTryGetValue/IsNullOrWhiteSpace. Files:DbContextItemBag.cs(x2),AuditSchemaInstaller.cs,UseAuditingTests.cs,SmallCoverageGapsTests.cs,MigrateTests.cs.UnusedParameter.Localx2 (src) —context→_in theConfigureServices/ConfigureAppConfigurationlambdas inProgram.csandIHostBuilderExtensions.cs.UnusedMember.Local(test) — deleted the single-argCreate(DbContext)overload from theUncachedModelCacheKeyFactorytest double; that signature is not part of the currentIModelCacheKeyFactoryinterface, so it was genuinely dead.Redundant*(x3) — dropped an explicit type argument onRoundTrip<byte[]>, an explicitobject?[]on aSerializecall, and a redundant default arg onnew StaticAuditUserProvider("u", null)→("u").UnusedAutoPropertyAccessor.Localx4 +UnusedMember.Localx1 — scoped// ReSharper disable UnusedAutoPropertyAccessor.Local/UnusedMember.Localblocks on three EF-hydrated test POCOs (MappedItem,Widget,Color.Red). EF reads these via reflection; R# can't see it.zizmor: 10 → 0
template-injectionpr.yamlcodeql-completion step andrelease.yamlNUGET_USER check now bind context values throughenv:and reference them as$env:…/"$NUGET_USER"in the run body.dependabot-cooldowncooldown: { default-days: 7 }to both dependabot ecosystems.artipackedintegration.yamlcheckout now setspersist-credentials: false.superfluous-actionssoftprops/action-gh-releasefor the runner-bundledgh release upload --clobber. Behavior unchanged — release exists (workflow only runs onrelease:published); this just attaches.dangerous-triggerspull_request_targetonpr.yamlwaived via newzizmor.ymlwith documented rationale. Full migration topull_requestis a workflow-wide refactor (1400+ lines, resolves the 7 ScorecardDangerousWorkflowIDfindings at the same time) — tracked separately, not landed here.Scorecard: 16 (already below the <25 bar; not touched here)
Left as-is for now, all tracked under the same follow-up as needed:
DangerousWorkflowIDx7 — all trace to the samepull_request_target+refs/pull/${{ pr.number }}/headcheckout pattern; resolved by the same migration asdangerous-triggers.PinnedDependenciesIDx5 —dotnet restorecalls; would need NuGet lockfiles across the repo. Fleet referencereference_lockfile_and_coverage_gate_release_trapsflags a known gh-pages interaction, so deferring.SASTID,CodeReviewID,CIIBestPracticesID,BranchProtectionID— repo/config-level, no file change would move them.Test-code changes (per
feedback_test_changes_need_approval— flagging for review)ModelBuilderConfigurationTests.cs— dropped an unused overload ofUncachedModelCacheKeyFactory.Createand removed a redundantnullarg onStaticAuditUserProvider.AuditCaptureColumnNameTests.cs,AuditCapturePostSaveSnapshotTests.cs,StringAuditValueSerializerExactFormatTests.cs— scoped ReSharper suppression comments on EF-hydrated POCOs.UseAuditingTests.cs,SmallCoverageGapsTests.cs,MigrateTests.cs,PipeDelimitedEntityKeySerializerTests.cs— removed redundant!/ explicit type args (S8969 / Redundant* rules).No test intent changed. All 99 affected unit tests still pass locally on
net10.0.Test plan
dotnet buildclean on all foursrc/projects in Releasedotnet buildclean on affected test projects in Releasenet10.0): 72 inEntityFrameworkCore.Tests.Unit+ 27 inCli.Tests.Unit--config zizmor.yml)gh api "repos/Chris-Wolfgang/AuditTrail/code-scanning/alerts?state=open" --jq 'length'returns a number that meets the DoD (target: InspectCode <25, Scorecard <25, zizmor 0)🤖 Generated with Claude Code