Actions: exclude mutable action tag rule from Semgrep scans (#11944)

We are not pedantic enough to pin Actions versions to a SHA.
Re-enable semgrep scans on previously-ignored .github/workflows and disable
yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
This commit is contained in:
Austin authored and GitHub committed 2026-09-21 19:09:28 +00:00
1 parent bf2ef8f2d6
commit 43479aa4e1
3 files changed
+4 -6

No files matched your search

+2 -1
View File
@@ -29,7 +29,8 @@ jobs:
semgrep \
--sarif --output report.sarif \
--metrics=off \
--config="p/default"
--config="p/default" \
--exclude-rule="yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag"
# step 3
- name: save report as pipeline artifact
+2 -1
View File
@@ -28,4 +28,5 @@ jobs:
--error \
--metrics=off \
--baseline-commit ${{ github.event.pull_request.base.sha }} \
--config="p/default"
--config="p/default" \
--exclude-rule="yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag"
-4
View File
@@ -1,7 +1,3 @@
.github/workflows/main_matrix.yml
.github/workflows/build_windows_bin.yml
.github/workflows/package_winget.yml
src/mesh/compression/unishox2.cpp
# Emscripten/WebUSB browser glue for the wasm node — not part of the firmware
# binary or its security surface. The format-string rule false-positives on its
# benign retry/diagnostic console logs.