Skip to content

ci: keep accepted Scorecard residuals out of code scanning - #43

Merged
agjs merged 1 commit into
mainfrom
fix/scorecard-sarif-filter
Aug 22, 2026
Merged

ci: keep accepted Scorecard residuals out of code scanning#43
agjs merged 1 commit into
mainfrom
fix/scorecard-sarif-filter

Conversation

@agjs

@agjs agjs commented Aug 22, 2026

Copy link
Copy Markdown
Collaborator

Summary

The five remaining Scorecard code-scanning alerts cannot reach a 10 on a one-maintainer template (second human reviewer, CII badge signup, historical CI/SAST, fuzzing). They were dismissed, but the weekly Scorecard SARIF upload would reopen them.

This keeps full results on scorecard.dev (publish_results: true) and strips only those residual rule IDs from the GitHub code-scanning upload.

Branch protection now requires two reviews (that finding is actually fixed).

@agjs
agjs merged commit 9b0b4c3 into main Aug 22, 2026
11 checks passed
@agjs
agjs deleted the fix/scorecard-sarif-filter branch August 22, 2026 20:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant