You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit aafade1
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: .agents/sow/done/SOW-0009-20260602-github-security-scanning.md
+15-4Lines changed: 15 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@
4
4
5
5
Status: completed
6
6
7
-
Sub-state: GitHub scanner automation is complete; the first pushed Supply Chain Security regression was repaired and validated locally.
7
+
Sub-state: GitHub scanner automation is complete; Supply Chain Security and CodeQL first-run regressions were repaired and validated locally.
8
8
9
9
## Requirements
10
10
@@ -330,24 +330,34 @@ What broke:
330
330
- First pushed GitHub run `26812274331` failed in `.github/workflows/supply-chain-security.yml`.
331
331
- OSV-Scanner job failed during tool installation because `github.com/google/osv-scanner/v2@v2.3.8` requires Go `>=1.26.2`, while the workflow installed Go `1.25.10` from `src/go/go.mod`.
332
332
- OpenSSF Scorecard job failed while publishing results because Scorecard rejects workflows with global `security-events: write`; the workflow had that permission at top level.
333
+
- First pushed GitHub run `26812274378` failed in `.github/workflows/codeql.yml`.
334
+
- Rust CodeQL failed because Rust does not support manual build mode.
335
+
- C/C++ CodeQL failed because the workflow built every CMake target and hit an existing GCC preprocessor issue in `tests/fixtures/c/test_stress.c:840`.
333
336
334
337
Evidence:
335
338
336
339
-`gh run view 26812274331 --repo netdata/plugin-ipc --json jobs` showed `OSV-Scanner` and `OpenSSF Scorecard` failed while `Semgrep CE` succeeded.
337
340
-`gh run view 26812274331 --repo netdata/plugin-ipc --log-failed` showed `requires go >= 1.26.2 (running go 1.25.10; GOTOOLCHAIN=local)`.
338
341
- The same log showed Scorecard publish failed with `global perm is set to write: permission for security-events is set to write`.
342
+
-`gh run view 26812274378 --repo netdata/plugin-ipc --json jobs` showed `Analyze Rust` and `Analyze C/C++` failed while `Analyze Go` succeeded.
343
+
- The CodeQL Rust log showed `Rust does not support the manual build mode. Please try using one of the following build modes instead: none`.
344
+
- The CodeQL C/C++ log showed `tests/fixtures/c/test_stress.c:840:46: error: missing binary operator before token "("`.
339
345
340
346
Why previous validation missed it:
341
347
342
348
- Local OSV ran under the workstation Go toolchain, which is newer than the SDK module `go.mod` version used by `actions/setup-go`.
343
349
- Local `actionlint` verifies workflow syntax but cannot validate Scorecard's runtime publishing restrictions.
350
+
- Local CodeQL was not run; `actionlint` cannot validate per-language CodeQL build-mode restrictions.
351
+
- Local full CMake used the workstation compiler environment, while the GitHub C/C++ CodeQL job used the hosted runner compiler path and built all tests.
344
352
345
353
Repair plan:
346
354
347
355
1. Use Go `1.26.x` only for the OSV-Scanner tool job.
348
356
2. Keep top-level workflow permissions read-only and move `security-events: write` to SARIF-uploading jobs.
0 commit comments