chore(deps+ci): SonarAnalyzer 10.32 + Scorecard SARIF filter (protected-only PR) - #318
Merged
Merged
Conversation
… SARIF (protected-only PR) Extracts the two protected files from the vNext → main bundle (PR #317) into a single admin-bypass PR so the bypass waiver only applies to these two vetted files, not to any future non-protected content that might accumulate on the bundle. Both files landed on vNext via their own reviewed PRs first: - `Directory.Build.props` — Dependabot bump SonarAnalyzer.CSharp 10.31.0.145097 → 10.32.0.713 (merged on vNext as PR #314). Sonar 10.32 introduces no new warnings on this repo; my #315 already added the `S8969` suppression in `tests/.editorconfig` for a Sonar rule that would otherwise trip on multi-TFM `Result<T>.Value!.FirstName`. - `.github/workflows/scorecard.yml` — SARIF filter step so `DangerousWorkflowID` and CLI `PinnedDependenciesID` findings are stripped BEFORE upload to Code Scanning, avoiding the dismissal-decay problem across weekly re-runs (merged on vNext as PR #316). `Detect .NET Projects` will fail on this PR by design — that guard's whole purpose is to force a manual eyeball on protected-file changes. Admin-bypass at merge is expected. After this merges to main, `main` == `vNext` at these two files, so PR #317 (vNext → main) becomes empty and can be closed. Refs: #309, #314, #316, #317 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Chris-Wolfgang
added a commit
that referenced
this pull request
Aug 20, 2026
Security PATCH round. Zero runtime behaviour changes to Wolfgang.TryPattern; every diff since v0.4.0 is workflow YAML, analyzer packages, or test-only files. Highlights (full detail in CHANGELOG): - SHA-pin all workflow actions to fleet-standard commit SHAs (+61 Scorecard PinnedDependenciesID alerts resolved). - Narrow semgrep-sast.yaml SARIF-upload permission to job-level (+1 TokenPermissionsID resolved). - Add durable jq SARIF filter in scorecard.yml for DangerousWorkflowID and CLI PinnedDependenciesID; raw SARIF still uploaded as workflow artifact (16 residual alerts drop to 0 on next weekly run). - InspectCode triage: 11 real findings fixed, 5 suppressed with justification at tests/.editorconfig. - Dependency bumps: SonarAnalyzer.CSharp 10.31→10.32, Microsoft.SourceLink.GitHub 10.0.301→10.0.400, Meziantou.Analyzer 3.0.125→3.0.156. Closes the fleet-wide 2026-08-13 code-scanning audit umbrella (#309) for this repo. Refs: #309, #311, #312, #314, #315, #316, #318 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Protected-only PR extracted from the vNext → main bundle (#317) so the admin-bypass waiver only covers these two vetted files, not any future non-protected content that might accumulate on the bundle. Follows the
protected-file-pr-splitskill flow.Files
Both landed on vNext via their own reviewed PRs already:
Directory.Build.props— Dependabot bump SonarAnalyzer.CSharp10.31.0.145097→10.32.0.713. Merged on vNext as #314. Sonar 10.32 introduces no new warnings on this repo; chore(security): SHA-pin actions, narrow permissions, triage InspectCode alerts #315 already added theS8969suppression intests/.editorconfigfor the Sonar rule that would otherwise trip on multi-TFMResult<T>.Value!.FirstName..github/workflows/scorecard.yml— adds ajqstep that filtersDangerousWorkflowIDand CLIPinnedDependenciesIDfindings out of the SARIF before upload to Code Scanning. Durably suppresses the 16 residual Scorecard alerts (avoiding the per-alert dismissal decay that made 7DangerousWorkflowIDalerts reappear with fresh alert numbers within hours). Merged on vNext as #316.Expected CI
Detect .NET Projects— fails by design, that's exactly the guard the split flow is built around. Admin-bypass at merge is expected.detect-projects.outputs.has-projects.Reviewer note
Two files, both trivial to eyeball:
Directory.Build.props— one-line version bump on a singlePackageReference.scorecard.yml— one new step + change upload path fromresults.sariftoresults-filtered.sarif. Raw SARIF still uploaded as workflow artifact for audit.After merge
mainback intovNext(or close & deletevNext, since the delta will be empty). PR #317 becomes empty and should be closed.gh workflow run scorecard.yml -R Chris-Wolfgang/Try-Pattern— expect open alert count to drop from 16 → 0.Refs: #309, #314, #316, #317
🤖 Generated with Claude Code