Skip to content

chore(deps+ci): SonarAnalyzer 10.32 + Scorecard SARIF filter (protected-only PR) - #318

Merged
Chris-Wolfgang merged 1 commit into
mainfrom
protected/vnext-config-bundle
Aug 20, 2026
Merged

Chris-Wolfgang merged 1 commit into
mainfrom
protected/vnext-config-bundle

Conversation

@Chris-Wolfgang

Copy link
Copy Markdown
Owner

Summary

Protected-only PR extracted from the vNext → main bundle (#317) so the admin-bypass waiver only covers these two vetted files, not any future non-protected content that might accumulate on the bundle. Follows the protected-file-pr-split skill flow.

Files

Both landed on vNext via their own reviewed PRs already:

  • Directory.Build.props — Dependabot bump SonarAnalyzer.CSharp 10.31.0.145097 → 10.32.0.713. Merged on vNext as #314. Sonar 10.32 introduces no new warnings on this repo; chore(security): SHA-pin actions, narrow permissions, triage InspectCode alerts #315 already added the S8969 suppression in tests/.editorconfig for the Sonar rule that would otherwise trip on multi-TFM Result<T>.Value!.FirstName.

  • .github/workflows/scorecard.yml — adds a jq step that filters DangerousWorkflowID and CLI PinnedDependenciesID findings out of the SARIF before upload to Code Scanning. Durably suppresses the 16 residual Scorecard alerts (avoiding the per-alert dismissal decay that made 7 DangerousWorkflowID alerts reappear with fresh alert numbers within hours). Merged on vNext as #316.

Expected CI

  • ❌ Detect .NET Projects — fails by design, that's exactly the guard the split flow is built around. Admin-bypass at merge is expected.
  • ⏭️ Stage 1/2/3 — SKIPPED because they depend on detect-projects.outputs.has-projects.
  • ✅ Everything else — Secrets Scan, DevSkim, CodeQL, SourceLink, Semgrep, InspectCode, license audit, AOT smoke, x-platform tests.

Reviewer note

Two files, both trivial to eyeball:

  • Directory.Build.props — one-line version bump on a single PackageReference.
  • scorecard.yml — one new step + change upload path from results.sarif to results-filtered.sarif. Raw SARIF still uploaded as workflow artifact for audit.

After merge

  • Merge main back into vNext (or close & delete vNext, since the delta will be empty). PR #317 becomes empty and should be closed.
  • Trigger manual Scorecard run: gh workflow run scorecard.yml -R Chris-Wolfgang/Try-Pattern — expect open alert count to drop from 16 → 0.
  • Close #309.
  • Consider v0.4.1 PATCH release.

Refs: #309, #314, #316, #317

🤖 Generated with Claude Code

… SARIF (protected-only PR)

Extracts the two protected files from the vNext → main bundle (PR #317)
into a single admin-bypass PR so the bypass waiver only applies to
these two vetted files, not to any future non-protected content that
might accumulate on the bundle.

Both files landed on vNext via their own reviewed PRs first:

- `Directory.Build.props` — Dependabot bump SonarAnalyzer.CSharp
  10.31.0.145097 → 10.32.0.713 (merged on vNext as PR #314). Sonar
  10.32 introduces no new warnings on this repo; my #315 already added
  the `S8969` suppression in `tests/.editorconfig` for a Sonar rule
  that would otherwise trip on multi-TFM `Result<T>.Value!.FirstName`.

- `.github/workflows/scorecard.yml` — SARIF filter step so
  `DangerousWorkflowID` and CLI `PinnedDependenciesID` findings are
  stripped BEFORE upload to Code Scanning, avoiding the dismissal-decay
  problem across weekly re-runs (merged on vNext as PR #316).

`Detect .NET Projects` will fail on this PR by design — that guard's
whole purpose is to force a manual eyeball on protected-file changes.
Admin-bypass at merge is expected.

After this merges to main, `main` == `vNext` at these two files, so
PR #317 (vNext → main) becomes empty and can be closed.

Refs: #309, #314, #316, #317

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings August 20, 2026 02:08

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@Chris-Wolfgang
Chris-Wolfgang merged commit eef3c10 into main Aug 20, 2026
17 of 18 checks passed
@Chris-Wolfgang
Chris-Wolfgang deleted the protected/vnext-config-bundle branch August 20, 2026 12:17
Chris-Wolfgang added a commit that referenced this pull request Aug 20, 2026
Security PATCH round. Zero runtime behaviour changes to
Wolfgang.TryPattern; every diff since v0.4.0 is workflow YAML,
analyzer packages, or test-only files.

Highlights (full detail in CHANGELOG):

- SHA-pin all workflow actions to fleet-standard commit SHAs (+61
  Scorecard PinnedDependenciesID alerts resolved).
- Narrow semgrep-sast.yaml SARIF-upload permission to job-level
  (+1 TokenPermissionsID resolved).
- Add durable jq SARIF filter in scorecard.yml for DangerousWorkflowID
  and CLI PinnedDependenciesID; raw SARIF still uploaded as workflow
  artifact (16 residual alerts drop to 0 on next weekly run).
- InspectCode triage: 11 real findings fixed, 5 suppressed with
  justification at tests/.editorconfig.
- Dependency bumps: SonarAnalyzer.CSharp 10.31→10.32,
  Microsoft.SourceLink.GitHub 10.0.301→10.0.400,
  Meziantou.Analyzer 3.0.125→3.0.156.

Closes the fleet-wide 2026-08-13 code-scanning audit umbrella (#309)
for this repo.

Refs: #309, #311, #312, #314, #315, #316, #318

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Maintenance] security: 92 open code-scanning alerts (2 tools)

2 participants