Repository navigation
ci: remove per-repo Semgrep scan (the Semgrep Code app covers PRs) - #780
Conversation
The semgrep-code-hyperpolymath GitHub App (Semgrep Managed Scans) already reports semgrep-cloud-platform/scan on every pull request here, so this workflow scanned the same code twice. No Semgrep context is required by any ruleset. actions.lock loses only the Semgrep-specific entries. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013aSu89DNALjTYHBvA6FcoM
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
💤 Files with no reviewable changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (10)
📝 SummarySummary by CodeRabbit
WalkthroughThe Semgrep GitHub Actions workflow was deleted. Its push, pull-request, scheduled and manual triggers, scan job, concurrency settings and SARIF upload step were removed. ChangesSecurity workflow
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to The change removes the repository-hosted Semgrep scan. No actionable merge-blocking issue is established, so it is mergeable after normal checks. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit watched the scan workflow go, Comment |
|



Summary
Removes this repo's own Semgrep scan. The
semgrep-code-hyperpolymathGitHub App (Semgrep Managed Scans) already reportssemgrep-cloud-platform/scanon every pull request here, so PRs were scanned twice. No ruleset requires a Semgrep context in this repo (checked viarules/branches/main).No issue. This is owner-requested estate cleanup (duplicate Semgrep scanning).
Type of change
📌 New pins
Head SHA:
81e3a33a9bc7527557549aeadb3a993427a39a84. No pins added or changed.github/codeql-action/upload-sarif@v4.38.2How has this been verified?
Files:
M .github/workflows/actions.lock
D .github/workflows/semgrep.yml
actions.lock: only the Semgrep-specific entries removed (thesemgrep.ymlworkflow key and/or thereturntocorp/semgrep-actionlist item and its dependency block). Every other entry, transitive dependencies included, is untouched.gh actions-lock --no-fix --json: findings diffed before/after. 0 new findings; only findings that belonged to the removed Semgrep entries disappeared.yq -e .parses every changed YAML file.Checklist
git commit -S, verifiedG).Notes for reviewers
Coverage change, stated rather than hidden: the removed workflow also ran on
pushandschedule. The app reports only on pull requests: nosemgrep-cloud-platform/scancheck exists onmainHEADbba281c. Default-branch and scheduled full scans now depend on Semgrep Cloud's own schedule, which is not verified from GitHub.🤖 Generated with Claude Code
https://claude.ai/code/session_013aSu89DNALjTYHBvA6FcoM