ci(security): filter Scorecard SARIF to durably suppress decided-not-fixed findings - #316
Merged
Merged
Conversation
…fixed findings Per-alert `gh api ... -X PATCH /code-scanning/alerts/<n>` dismissals do not persist across weekly Scorecard re-runs because SARIF fingerprints drift each run. #309 saw 7 DangerousWorkflowID alerts return with fresh alert numbers (194-188 vs the originally-dismissed 73-79) within hours of the dismissals. Filter the SARIF with `jq` BEFORE upload so these categories never enter Code Scanning in the first place: - **DangerousWorkflowID (7 alerts).** pr.yaml intentionally uses `pull_request_target` with `refs/pull/*/head`. The untrusted checkout is safely contained by the trusted-config re-fetch from origin/main, `persist-credentials: false`, and top-level `contents: read`. This is documented at pr.yaml's header and reviewed as intentional. - **PinnedDependenciesID / CLI (9 alerts).** `pipCommand`, `nugetCommand`, and `downloadThenRun` findings for shell invocations like `pip install semgrep==1.144.0`, `dotnet tool install ... --version`, and `curl ... | sha256sum -c` — all pinned by version at the command line where SHA-pinning is meaningful. SHA-pinning is not applicable to arbitrary CLI subcommands. `PinnedDependenciesID` findings for actual GitHub Actions (which CAN be SHA-pinned and which #315 just cleaned up) still flow through — those are not filtered. The raw unfiltered SARIF is still uploaded as the `scorecard-results` workflow artifact for audit, so nothing is hidden — only the Code Scanning ingest is filtered. Expected effect on next Scorecard run: - Scorecard open alerts: 16 → 0. Refs: #309 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
3 tasks
Chris-Wolfgang
added a commit
that referenced
this pull request
Aug 20, 2026
Security PATCH round. Zero runtime behaviour changes to Wolfgang.TryPattern; every diff since v0.4.0 is workflow YAML, analyzer packages, or test-only files. Highlights (full detail in CHANGELOG): - SHA-pin all workflow actions to fleet-standard commit SHAs (+61 Scorecard PinnedDependenciesID alerts resolved). - Narrow semgrep-sast.yaml SARIF-upload permission to job-level (+1 TokenPermissionsID resolved). - Add durable jq SARIF filter in scorecard.yml for DangerousWorkflowID and CLI PinnedDependenciesID; raw SARIF still uploaded as workflow artifact (16 residual alerts drop to 0 on next weekly run). - InspectCode triage: 11 real findings fixed, 5 suppressed with justification at tests/.editorconfig. - Dependency bumps: SonarAnalyzer.CSharp 10.31→10.32, Microsoft.SourceLink.GitHub 10.0.301→10.0.400, Meziantou.Analyzer 3.0.125→3.0.156. Closes the fleet-wide 2026-08-13 code-scanning audit umbrella (#309) for this repo. Refs: #309, #311, #312, #314, #315, #316, #318 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Per-alert
gh api ... -X PATCH /code-scanning/alerts/<n>dismissals do not persist across weekly Scorecard re-runs because SARIF fingerprints drift each run. #309 saw 7DangerousWorkflowIDalerts return with fresh alert numbers (194–188 vs the originally-dismissed 73–79) within hours of the dismissals.This PR adds a
jqstep inscorecard.ymlthat filters the SARIF before upload to Code Scanning, so the categories we've decided not to fix never enter the alert list in the first place.What's filtered (with rationale)
DangerousWorkflowID(7 alerts).pr.yamlintentionally usespull_request_targetwithrefs/pull/*/head. The untrusted checkout is safely contained by the trusted-config re-fetch fromorigin/main,persist-credentials: false, and top-levelcontents: read. Documented atpr.yaml's header.PinnedDependenciesID/ CLI (9 alerts).pipCommand,nugetCommand, anddownloadThenRunfindings for shell invocations likepip install semgrep==1.144.0,dotnet tool install … --version, andcurl … | sha256sum -c— all pinned by version at the command line, which is where SHA-pinning is meaningful for CLIs.PinnedDependenciesIDfindings for actual GitHub Actions (which CAN be SHA-pinned, and which chore(security): SHA-pin actions, narrow permissions, triage InspectCode alerts #315 just cleaned up) still flow through — the filter matches onpipCommand|nugetCommand|downloadThenRunin the message text, not on the whole rule.Audit trail
The raw unfiltered SARIF is still uploaded as the
scorecard-resultsworkflow artifact for 30 days. Only the Code Scanning ingest is filtered, so nothing is hidden — a maintainer can always download the raw results to see everything Scorecard emitted.Test plan
workflow_dispatch), verifygh api "repos/Chris-Wolfgang/Try-Pattern/code-scanning/alerts?state=open&tool_name=Scorecard" --paginate --jq 'length'= 0.scorecard-resultsartifact still contains the unfiltered SARIF (i.e. ajq '.runs[].results | length'on the downloaded artifact should return the pre-filter count).Refs: #309
🤖 Generated with Claude Code