Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/gitleaks.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -107,7 +107,7 @@ jobs:

- name: Upload SARIF to GitHub Code Scanning
if: always() && inputs.upload-sarif

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

continue-on-error allows SARIF upload failure to produce a green workflow without code-scanning results or PR annotations. Please surface the failure, or explicitly gate the upload on token capability and report the skipped state.

uses: github/codeql-action/upload-sarif@v4.37.4
uses: github/codeql-action/upload-sarif@v4.38.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There is no representative caller run for this changed upload-sarif path at the PR head. Please validate successful scans, detected secrets, SARIF upload, artifact fallback, and restricted-token behavior before treating the reusable workflow as ready.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This third-party action remains tag-pinned while the job has security-events: write. Please pin the action to a verified commit SHA and retain the version in a comment.

continue-on-error: true
with:
sarif_file: gitleaks-report.sarif
Expand Down