Repository navigation
ci: drop the GitGuardian job; relock without losing reusable edges - #127
Merged
Merged
Conversation
ggshield-action is in neither standards allowlist canon, the repo has no GITGUARDIAN_API_KEY secret, and the estate secret scanner (secret-scanner.yml) already runs. Owner ruling 2026-10-08. The lock is regenerated (it was valid:false on main: Dependabot moved sonarqube-scan-action to v8.3.0 and codeql-action to v4.38.2 without a relock). The regeneration drops the eight SHA-form transitive entries that #123 pinned for called reusables, so they are carried over verbatim. gh actions-lock --verify-local: valid:true (one advisory sha-as-ref, pre-existing). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw
Contributor
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Removes the GitGuardian job from
ci-benchmarks.ymland relocksactions.lock.GitGuardian/ggshield-actionis in neither standards allowlist canon, so governance / Allowlist Preflight cannot pass while the job exists. The repo also has noGITGUARDIAN_API_KEYsecret (the only Actions secret isFARM_DISPATCH_TOKEN), so the job could not have scanned anything. Secret scanning is already covered bysecret-scanner.yml(standardssecret-scanner-reusable.yml). Owner ruling, 2026-10-08. The same change landed in knot-rider (fix(ci): root-allow hygiene, wiki .md allowance, drop GitGuardian job knot-rider#78).needs:gitguardian. The header comment and job numbering are renumbered to match.actions.lockwas alreadyvalid:falseonmain: Dependabot movedsonarqube-scan-actionto v8.3.0 andcodeql-actionto v4.38.2 without a relock. The lock is now regenerated with standardsscripts/update-actions-lock.sh. The regeneration dropped the eight SHA-form transitive entries that fix(ci): reconcile actions.lock so the lockfile validates #123 pinned for the called standards reusables (actions/cache@55cc834…,ossf/scorecard-action@2d11466…,webfactory/ssh-agent@e838748…, …), so they are carried over byte for byte.Closes: no issue.
Type of change
📌 New pins
Head SHA:
9d5cd8acb3783a9e42308acfde26e0ea5ffdf42cChanged in
actions.lock(Dependabot already made these changes in the workflows; this PR only records them in the lock):sonarsource/sonarqube-scan-action@v8.3.0→d209202bc7d53ff1cc128f7f907dac145c9d6ae9(was v8.2.2ba9859e)github/codeql-action@v4.38.2→2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2(was v4.38.0b96794f)Removed:
gitguardian/ggshield-action@v1.54.0(7059aef). No workflowuses:line changed.How has this been verified?
gh actions-lock --verify-local --json=valid,findings→valid:true. The only finding is the advisorysha-as-refonjulia-actions/setup-julia@fa02766…, which was already there. Onmainthe result isvalid:false, with 7 findings.uses:across.github/workflows/*.ymlis byte-identical before and after the relock (sorted diff, empty).scripts/check-allowed-actions.shwithrhodium-standard-repositories/actions-allowlist/allowed-actions.json: "checked 20uses:refs — 0 not covered".yqparsesci-benchmarks.yml.Checklist
git commit -S):%G?=G.Notes for reviewers
Any future
gh actions-lockregeneration will drop the eight SHA-form reusable edges again. Re-append them, or regenerate with a tool that follows reusables.🤖 Generated with Claude Code
https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw