fix(ci): pin codeql-action to commit SHA (fixes OSSF Scorecard badge) - #410
Merged
Merged
Conversation
github/codeql-action/*@e4c79b4… pinned the *annotated tag object* for v4, not a commit. GitHub Actions resolves it fine, but OSSF Scorecard's scorecard-webapp rejects the publish as an "imposter commit" (HTTP 400: "e4c79b4… does not belong to github/codeql-action/upload-sarif"), so the repo is never ingested into the OSSF API and the README Scorecard badge renders the resulting 404 as "invalid repo path". Replace with the commit the tag points to (e0647621…, byte-identical v4 code) across all five pins (codeql init/analyze, pr/scorecard/semgrep upload-sarif). No version or behavior change. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This was referenced Aug 19, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The README OpenSSF Scorecard badge shows "invalid repo path" (red).
Root cause is not the badge markup or ingestion lag. The OSSF scorecard-webapp rejects every publish from this repo:
e4c79b4…is the annotated tag object for codeql-actionv4, not a commit (GET /commits/e4c79b4…→ 422 "No commit found"). GitHub Actions resolves a tag-object SHA, but OSSF's imposter-commit verifier requires a real commit SHA — so ingestion fails and shields.io renders the OSSF 404 as "invalid repo path".Sibling repos that pin real commit SHAs (ETL-Xml, ETL-FixedWidth, …) are ingested same-day; the only two org repos that 404 (ETL-Abstractions, ETL-DbClient) are exactly the two pinning tag objects.
Fix
Replace
e4c79b4…(tag object) →e0647621…(the commit that tag points to — byte-identical v4 code) across all five pins:codeql.yamlinit + analyzepr.yaml/scorecard.yaml/semgrep.yamlupload-sarifNo version or behavior change. After this merges to
main, the next scorecard run publishes successfully and the badge resolves.Notes
.github/workflows/*files → admin-bypass merge.main(scorecard publishes only from the default branch).🤖 Generated with Claude Code