You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit b9c56d6
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: .agents/sow/done/SOW-0009-20260602-github-security-scanning.md
+9-4Lines changed: 9 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@
4
4
5
5
Status: completed
6
6
7
-
Sub-state: GitHub scanner automation is complete; Supply Chain Securityand CodeQL first-run regressions were repaired and validated locally.
7
+
Sub-state: GitHub scanner automation is complete; Supply Chain Security, CodeQL, and Static Analysis first-run regressions were repaired and validated locally.
8
8
9
9
## Requirements
10
10
@@ -333,6 +333,7 @@ What broke:
333
333
- First pushed GitHub run `26812274378` failed in `.github/workflows/codeql.yml`.
334
334
- Rust CodeQL failed because Rust does not support manual build mode.
335
335
- C/C++ CodeQL failed because the workflow built every CMake target and hit an existing GCC preprocessor issue in `tests/fixtures/c/test_stress.c:840`.
336
+
- First pushed final Static Analysis run `26812569114` failed in the C Static Analysis job because it also built every CMake target before running library-scoped analyzers.
336
337
337
338
Evidence:
338
339
@@ -342,22 +343,25 @@ Evidence:
342
343
-`gh run view 26812274378 --repo netdata/plugin-ipc --json jobs` showed `Analyze Rust` and `Analyze C/C++` failed while `Analyze Go` succeeded.
343
344
- The CodeQL Rust log showed `Rust does not support the manual build mode. Please try using one of the following build modes instead: none`.
344
345
- The CodeQL C/C++ log showed `tests/fixtures/c/test_stress.c:840:46: error: missing binary operator before token "("`.
346
+
-`gh run view 26812569114 --repo netdata/plugin-ipc --json jobs` showed `C Static Analysis` failed at `Build C targets`, while Go and workflow/shell jobs completed successfully.
345
347
346
348
Why previous validation missed it:
347
349
348
350
- Local OSV ran under the workstation Go toolchain, which is newer than the SDK module `go.mod` version used by `actions/setup-go`.
349
351
- Local `actionlint` verifies workflow syntax but cannot validate Scorecard's runtime publishing restrictions.
350
352
- Local CodeQL was not run; `actionlint` cannot validate per-language CodeQL build-mode restrictions.
351
353
- Local full CMake used the workstation compiler environment, while the GitHub C/C++ CodeQL job used the hosted runner compiler path and built all tests.
354
+
- The Static Analysis C job had the same over-broad build step as the original CodeQL C/C++ job.
352
355
353
356
Repair plan:
354
357
355
358
1. Use Go `1.26.x` only for the OSV-Scanner tool job.
356
359
2. Keep top-level workflow permissions read-only and move `security-events: write` to SARIF-uploading jobs.
357
360
3. Use CodeQL `build-mode: none` for Rust.
358
361
4. Limit C/C++ CodeQL manual build to the C library targets.
0 commit comments