Skip to content

ci: drop the GitGuardian job; relock without losing reusable edges - #127

Merged
hyperpolymath merged 1 commit into
mainfrom
ci/drop-ggshield
Oct 8, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
ci/drop-ggshield

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Removes the GitGuardian job from ci-benchmarks.yml and relocks actions.lock.

  • GitGuardian/ggshield-action is in neither standards allowlist canon, so governance / Allowlist Preflight cannot pass while the job exists. The repo also has no GITGUARDIAN_API_KEY secret (the only Actions secret is FARM_DISPATCH_TOKEN), so the job could not have scanned anything. Secret scanning is already covered by secret-scanner.yml (standards secret-scanner-reusable.yml). Owner ruling, 2026-10-08. The same change landed in knot-rider (fix(ci): root-allow hygiene, wiki .md allowance, drop GitGuardian job knot-rider#78).
  • No other job needs: gitguardian. The header comment and job numbering are renumbered to match.
  • actions.lock was already valid:false on main: Dependabot moved sonarqube-scan-action to v8.3.0 and codeql-action to v4.38.2 without a relock. The lock is now regenerated with standards scripts/update-actions-lock.sh. The regeneration dropped the eight SHA-form transitive entries that fix(ci): reconcile actions.lock so the lockfile validates #123 pinned for the called standards reusables (actions/cache@55cc834…, ossf/scorecard-action@2d11466…, webfactory/ssh-agent@e838748…, …), so they are carried over byte for byte.

Closes: no issue.

Type of change

  • 🐛 Bug fix — n/a
  • ✨ New feature — n/a
  • 💥 Breaking change — n/a
  • 🕳️ Soundness fix — n/a
  • 📖 Documentation — n/a
  • 🧹 Refactor / tech debt — n/a
  • ⚡ Performance — n/a
  • 🔧 Build / CI / tooling

📌 New pins

Head SHA: 9d5cd8acb3783a9e42308acfde26e0ea5ffdf42c

Changed in actions.lock (Dependabot already made these changes in the workflows; this PR only records them in the lock):

  • sonarsource/sonarqube-scan-action@v8.3.0 → d209202bc7d53ff1cc128f7f907dac145c9d6ae9 (was v8.2.2 ba9859e)
  • github/codeql-action@v4.38.2 → 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 (was v4.38.0 b96794f)

Removed: gitguardian/ggshield-action@v1.54.0 (7059aef). No workflow uses: line changed.

How has this been verified?

  • gh actions-lock --verify-local --json=valid,findings → valid:true. The only finding is the advisory sha-as-ref on julia-actions/setup-julia@fa02766…, which was already there. On main the result is valid:false, with 7 findings.
  • Every uses: across .github/workflows/*.yml is byte-identical before and after the relock (sorted diff, empty).
  • The two new commit SHAs match the ones already in hyperpolymath/knot-rider's lock for the same tags.
  • standards scripts/check-allowed-actions.sh with rhodium-standard-repositories/actions-allowlist/allowed-actions.json: "checked 20 uses: refs — 0 not covered".
  • yq parses ci-benchmarks.yml.

Checklist

  • My commits are signed (git commit -S): %G? = G.
  • I ran the project's own checks locally: only the lock and allowlist checks above apply. No code changed, so no tests were run.
  • New files carry the correct SPDX header — n/a: no new files.
  • Docs are updated: the workflow's header comment no longer lists GitGuardian.
  • I have not introduced a soundness hole. This removes one secret scanner whose key was never set; the estate scanner still runs.

Notes for reviewers

Any future gh actions-lock regeneration will drop the eight SHA-form reusable edges again. Re-append them, or regenerate with a tool that follows reusables.

🤖 Generated with Claude Code

https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw

ggshield-action is in neither standards allowlist canon, the repo has
no GITGUARDIAN_API_KEY secret, and the estate secret scanner
(secret-scanner.yml) already runs. Owner ruling 2026-10-08.

The lock is regenerated (it was valid:false on main: Dependabot moved
sonarqube-scan-action to v8.3.0 and codeql-action to v4.38.2 without a
relock). The regeneration drops the eight SHA-form transitive entries
that #123 pinned for called reusables, so they are carried over
verbatim. gh actions-lock --verify-local: valid:true (one advisory
sha-as-ref, pre-existing).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw
@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 152372bb-5200-4fb1-af03-046d14819df5
📥 Commits

Reviewing files that changed from the base of the PR and between c8ec6e8 and 9d5cd8a.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (1)
  • .github/workflows/ci-benchmarks.yml
 _________________________________________________________________
< Granted, I'm not human, but I still know when your code is bad. >
 -----------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit e47f904 into main Oct 8, 2026
29 of 32 checks passed
@hyperpolymath
hyperpolymath deleted the ci/drop-ggshield branch October 8, 2026 11:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant