Skip to content

fix(ci): pin codeql-action to commit SHA (fixes OSSF Scorecard badge) - #410

Merged
Chris-Wolfgang merged 1 commit into
mainfrom
fix/scorecard-imposter-commit-pin
Aug 18, 2026
Merged

Chris-Wolfgang merged 1 commit into
mainfrom
fix/scorecard-imposter-commit-pin

Conversation

@Chris-Wolfgang

Copy link
Copy Markdown
Owner

Problem

The README OpenSSF Scorecard badge shows "invalid repo path" (red).

Root cause is not the badge markup or ingestion lag. The OSSF scorecard-webapp rejects every publish from this repo:

error sending scorecard results to webapp: 400 Bad Request
"workflow verification failed: imposter commit:
 e4c79b4e9ebfe577d446333c2e31ed81079e7b03 does not belong to
 github/codeql-action/upload-sarif"

e4c79b4… is the annotated tag object for codeql-action v4, not a commit (GET /commits/e4c79b4… → 422 "No commit found"). GitHub Actions resolves a tag-object SHA, but OSSF's imposter-commit verifier requires a real commit SHA — so ingestion fails and shields.io renders the OSSF 404 as "invalid repo path".

Sibling repos that pin real commit SHAs (ETL-Xml, ETL-FixedWidth, …) are ingested same-day; the only two org repos that 404 (ETL-Abstractions, ETL-DbClient) are exactly the two pinning tag objects.

Fix

Replace e4c79b4… (tag object) → e0647621… (the commit that tag points to — byte-identical v4 code) across all five pins:

  • codeql.yaml init + analyze
  • pr.yaml / scorecard.yaml / semgrep.yaml upload-sarif

No version or behavior change. After this merges to main, the next scorecard run publishes successfully and the badge resolves.

Notes

  • Touches protected .github/workflows/* files → admin-bypass merge.
  • Must land on main (scorecard publishes only from the default branch).

🤖 Generated with Claude Code

github/codeql-action/*@e4c79b4… pinned the *annotated tag object* for v4,
not a commit. GitHub Actions resolves it fine, but OSSF Scorecard's
scorecard-webapp rejects the publish as an "imposter commit" (HTTP 400:
"e4c79b4… does not belong to github/codeql-action/upload-sarif"), so the
repo is never ingested into the OSSF API and the README Scorecard badge
renders the resulting 404 as "invalid repo path".

Replace with the commit the tag points to (e0647621…, byte-identical v4
code) across all five pins (codeql init/analyze, pr/scorecard/semgrep
upload-sarif). No version or behavior change.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings August 17, 2026 23:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants