From 81e3a33a9bc7527557549aeadb3a993427a39a84 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 8 Oct 2026 11:42:04 +0100 Subject: [PATCH] ci: remove per-repo Semgrep scan; the Semgrep Code app covers PRs The semgrep-code-hyperpolymath GitHub App (Semgrep Managed Scans) already reports semgrep-cloud-platform/scan on every pull request here, so this workflow scanned the same code twice. No Semgrep context is required by any ruleset. actions.lock loses only the Semgrep-specific entries. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_013aSu89DNALjTYHBvA6FcoM --- .github/workflows/actions.lock | 3 --- .github/workflows/semgrep.yml | 37 ---------------------------------- 2 files changed, 40 deletions(-) delete mode 100644 .github/workflows/semgrep.yml diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index aad9bf21..60421cbc 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -54,9 +54,6 @@ workflows: '.github/workflows/scorecard.yml': [] '.github/workflows/secret-scanner.yml': - 'actions/checkout@v7.0.1' - '.github/workflows/semgrep.yml': - - 'actions/checkout@v7.0.1' - - 'github/codeql-action@v4.38.0' '.github/workflows/spark-theatre-gate.yml': [] '.github/workflows/stdlib-naming.yml': - 'actions/checkout@v7.0.1' diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml deleted file mode 100644 index a863a658..00000000 --- a/.github/workflows/semgrep.yml +++ /dev/null @@ -1,37 +0,0 @@ -# This workflow is managed by gh actions-lock. -# SPDX-License-Identifier: MPL-2.0 -# This workflow is managed by gh actions-lock. -# This workflow is managed by gh actions-lock. -name: Semgrep SAST -on: - push: - branches: [main] - pull_request: - branches: [main] - schedule: - - cron: '0 5 * * 1' - workflow_dispatch: -permissions: read-all -# Actions concurrency pool. Applied only to read-only check workflows -# (no publish/mutation), so cancelling a superseded run is always safe. -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true -jobs: - semgrep: - runs-on: ubuntu-latest - timeout-minutes: 10 - permissions: - security-events: write - contents: read - container: - image: semgrep/semgrep - steps: - - uses: actions/checkout@v7.0.1 - - name: Run Semgrep - run: semgrep scan --sarif --output=semgrep.sarif --config=auto . - - name: Upload SARIF - uses: github/codeql-action/upload-sarif@v4.38.2 - with: - sarif_file: semgrep.sarif - if: always()