ci: remove retired Semgrep action - #740
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
💤 Files with no reviewable changes (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (22)
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe security workflow removes the primary and audit Semgrep jobs. It also removes their dependencies and status output entries. CodeQL remains the only SAST job described in the workflow. ChangesSecurity workflow
Estimated code review effort: 1 (Trivial) | ~3 minutes Merge Risk: ⚪ Minimal · up to This localized change removes retired Semgrep workflow jobs and stale lockfile references without altering unrelated repository controls; no actionable merge-blocking risk remains after normal checks and review. Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Full details: Docstring CoverageExplanation No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. ✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Scope
Removes the two direct
returntocorp/semgrep-action@v1jobs from.github/workflows/security-policy.yml, updates only their dependent summary references, and removes the exact stale action and workflow mapping from.github/workflows/actions.lock.Validation
rgconfirms no remainingreturntocorp/semgrep-actionreference under.github/workflows.gh actions-lock --no-fixscanned 29 workflows; it reported only existingmisetool-registry/cache warnings, with no actions-lock finding.git diff --checkpassed.Deliberately not changed
No Actions allowlists, repository rules, branch/tag protection, or unrelated workflow findings were changed.