Skip to content

ci: remove per-repo Semgrep scan (the Semgrep Code app covers PRs) - #780

Merged
hyperpolymath merged 1 commit into
mainfrom
chore/drop-duplicate-semgrep
Oct 8, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
chore/drop-duplicate-semgrep

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Removes this repo's own Semgrep scan. The semgrep-code-hyperpolymath GitHub App (Semgrep Managed Scans) already reports semgrep-cloud-platform/scan on every pull request here, so PRs were scanned twice. No ruleset requires a Semgrep context in this repo (checked via rules/branches/main).

No issue. This is owner-requested estate cleanup (duplicate Semgrep scanning).

Type of change

  • 🐛 Bug fix: n/a
  • ✨ New feature: n/a
  • 💥 Breaking change: no. No required check is removed.
  • 🕳️ Soundness fix: n/a
  • 📖 Documentation: n/a
  • 🧹 Refactor / tech debt: n/a
  • ⚡ Performance: n/a
  • 🔧 Build / CI / tooling

📌 New pins

Head SHA: 81e3a33a9bc7527557549aeadb3a993427a39a84. No pins added or changed.

  • removed: github/codeql-action/upload-sarif@v4.38.2

How has this been verified?

Files:
M .github/workflows/actions.lock
D .github/workflows/semgrep.yml

actions.lock: only the Semgrep-specific entries removed (the semgrep.yml workflow key and/or the returntocorp/semgrep-action list item and its dependency block). Every other entry, transitive dependencies included, is untouched.

  • gh actions-lock --no-fix --json: findings diffed before/after. 0 new findings; only findings that belonged to the removed Semgrep entries disappeared.
  • yq -e . parses every changed YAML file.

Checklist

  • My commits are signed (git commit -S, verified G).
  • I ran the project's own checks/tests locally and they pass: the workflow checks above. The change is CI-only, so no build or test was affected.
  • New files carry the correct SPDX identifier: n/a, no new files.
  • Docs are updated: see notes. Prose that mentions Semgrep is left as is.
  • I have not introduced a soundness hole. The coverage change is flagged below.

Notes for reviewers

Coverage change, stated rather than hidden: the removed workflow also ran on push and schedule. The app reports only on pull requests: no semgrep-cloud-platform/scan check exists on main HEAD bba281c. Default-branch and scheduled full scans now depend on Semgrep Cloud's own schedule, which is not verified from GitHub.

🤖 Generated with Claude Code

https://claude.ai/code/session_013aSu89DNALjTYHBvA6FcoM

The semgrep-code-hyperpolymath GitHub App (Semgrep Managed Scans) already
reports semgrep-cloud-platform/scan on every pull request here, so this
workflow scanned the same code twice. No Semgrep context is required by
any ruleset. actions.lock loses only the Semgrep-specific entries.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013aSu89DNALjTYHBvA6FcoM
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 617ea9d5-5d36-47b2-bef3-1c7c63d785c3
📥 Commits

Reviewing files that changed from the base of the PR and between bba281c and 81e3a33.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (1)
  • .github/workflows/semgrep.yml
💤 Files with no reviewable changes (1)
  • .github/workflows/semgrep.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (10)
  • GitHub Check: GitGuardian Security Checks
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: hypatia / Hypatia Neurosymbolic Analysis
  • GitHub Check: coverage-visibility
  • GitHub Check: lint
  • GitHub Check: migration-assistant
  • GitHub Check: vscode-smoke
  • GitHub Check: build
  • GitHub Check: bench-visibility
  • GitHub Check: scan

📝 Summary

Summary by CodeRabbit

  • Chores
    • Automated code security scans no longer run on changes, on a weekly schedule, or when manually requested.
    • Scan results are no longer uploaded to the project’s security reports. These changes affect project maintenance and do not alter end-user features.

Walkthrough

The Semgrep GitHub Actions workflow was deleted. Its push, pull-request, scheduled and manual triggers, scan job, concurrency settings and SARIF upload step were removed.

Changes

Security workflow

Layer / File(s) Summary
Remove Semgrep workflow
.github/workflows/semgrep.yml
The workflow and its triggers, concurrency settings, Semgrep scan and SARIF upload step were removed.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Suggested reviewers: metadatastician

Merge Risk: ⚪ Minimal · up to 81e3a

The change removes the repository-hosted Semgrep scan. No actionable merge-blocking issue is established, so it is mergeable after normal checks.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the removal of the repository-level Semgrep scan because the Semgrep Code app covers pull requests.
Description check ✅ Passed The description is directly related to the changes. It explains the duplicate scan removal, verification steps, and the change to push and scheduled scan coverage.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit watched the scan workflow go,
Then hopped past logs that used to show.
No Monday run, no button press,
No SARIF upload to process.
The burrow grows quiet; the carrots stay.

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 8, 2026

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath merged commit e8f6a71 into main Oct 8, 2026
21 checks passed
@hyperpolymath
hyperpolymath deleted the chore/drop-duplicate-semgrep branch October 8, 2026 11:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant