From 3328f27ca7861cf76a2f8fada98efca9833c955a Mon Sep 17 00:00:00 2001 From: Chris Wolfgang <210299580+Chris-Wolfgang@users.noreply.github.com> Date: Wed, 19 Aug 2026 22:07:51 -0400 Subject: [PATCH] =?UTF-8?q?chore(deps):=20bump=20SonarAnalyzer.CSharp=2010?= =?UTF-8?q?.31=E2=86=9210.32=20+=20filter=20Scorecard=20SARIF=20(protected?= =?UTF-8?q?-only=20PR)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Extracts the two protected files from the vNext → main bundle (PR #317) into a single admin-bypass PR so the bypass waiver only applies to these two vetted files, not to any future non-protected content that might accumulate on the bundle. Both files landed on vNext via their own reviewed PRs first: - `Directory.Build.props` — Dependabot bump SonarAnalyzer.CSharp 10.31.0.145097 → 10.32.0.713 (merged on vNext as PR #314). Sonar 10.32 introduces no new warnings on this repo; my #315 already added the `S8969` suppression in `tests/.editorconfig` for a Sonar rule that would otherwise trip on multi-TFM `Result.Value!.FirstName`. - `.github/workflows/scorecard.yml` — SARIF filter step so `DangerousWorkflowID` and CLI `PinnedDependenciesID` findings are stripped BEFORE upload to Code Scanning, avoiding the dismissal-decay problem across weekly re-runs (merged on vNext as PR #316). `Detect .NET Projects` will fail on this PR by design — that guard's whole purpose is to force a manual eyeball on protected-file changes. Admin-bypass at merge is expected. After this merges to main, `main` == `vNext` at these two files, so PR #317 (vNext → main) becomes empty and can be closed. Refs: #309, #314, #316, #317 Co-Authored-By: Claude Opus 4.7 --- .github/workflows/scorecard.yml | 45 +++++++++++++++++++++++++++++++-- Directory.Build.props | 2 +- 2 files changed, 44 insertions(+), 3 deletions(-) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index d185eae..d5fd018 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -64,7 +64,48 @@ jobs: # don't want in-flight PR scores polluting the badge. publish_results: ${{ github.event_name != 'pull_request' }} - - name: Upload artifact (JSON copy) + - name: Filter SARIF (durable suppression of decided-not-fixed findings) + # Scorecard's per-alert dismissals via `gh api ... -X PATCH + # /code-scanning/alerts/` do not persist across weekly re-runs + # because SARIF fingerprints drift each run (session memory: + # reference_scorecard_dismissal_not_durable). This step strips + # findings we've explicitly decided not to fix from the SARIF + # BEFORE upload, so they never enter Code Scanning in the first + # place. Rationale for each filter is inline below. + # + # Preserves the raw unfiltered SARIF in the "scorecard-results" + # artifact for audit — only the Code Scanning ingest is filtered. + run: | + jq ' + .runs[].results |= map(select( + # DangerousWorkflowID: pr.yaml uses pull_request_target with + # refs/pull/*/head by intentional design. The untrusted + # checkout is safely contained by the "Fetch trusted config + # from main" step, persist-credentials:false, and a + # top-level contents:read permission. Documented at pr.yaml + # header. Scorecard flags the pattern; we do not fix. + (.ruleId != "DangerousWorkflowID") + and + # PinnedDependenciesID for pipCommand / nugetCommand / + # downloadThenRun: these are CLI invocations inside `run:` + # steps (e.g. `pip install semgrep==...`, `dotnet tool + # install ...`, `curl ... | bash`). They are already pinned + # by version at the command line where meaningful, and + # SHA-pinning is not applicable to arbitrary CLI subcommands. + # PinnedDependenciesID findings for actual GitHub Actions + # (which CAN be SHA-pinned) still flow through — those are + # not filtered out. + ( + .ruleId != "PinnedDependenciesID" + or (.message.text | test("pipCommand|nugetCommand|downloadThenRun") | not) + ) + )) + ' results.sarif > results-filtered.sarif + before=$(jq '[.runs[].results[]] | length' results.sarif) + after=$(jq '[.runs[].results[]] | length' results-filtered.sarif) + echo "Filtered SARIF: ${before} → ${after} findings ($((before - after)) suppressed)." + + - name: Upload artifact (raw SARIF, for audit) uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: scorecard-results @@ -74,4 +115,4 @@ jobs: - name: Upload results to Code Scanning uses: github/codeql-action/upload-sarif@5595ccaf912efad79be6eef63a5619ff05969be3 # v4 with: - sarif_file: results.sarif + sarif_file: results-filtered.sarif diff --git a/Directory.Build.props b/Directory.Build.props index e6bd330..aa26945 100644 --- a/Directory.Build.props +++ b/Directory.Build.props @@ -59,7 +59,7 @@ - + all runtime; build; native; contentfiles; analyzers; buildtransitive