From 43479aa4e1023b7154196fce4867bbcd7ba63f79 Mon Sep 17 00:00:00 2001 From: Austin Date: Mon, 21 Sep 2026 19:09:28 +0000 Subject: [PATCH] Actions: exclude mutable action tag rule from Semgrep scans (#11944) We are not pedantic enough to pin Actions versions to a SHA. Re-enable semgrep scans on previously-ignored .github/workflows and disable yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag --- .github/workflows/sec_sast_semgrep_cron.yml | 3 ++- .github/workflows/sec_sast_semgrep_pull.yml | 3 ++- .semgrepignore | 4 ---- 3 files changed, 4 insertions(+), 6 deletions(-) diff --git a/.github/workflows/sec_sast_semgrep_cron.yml b/.github/workflows/sec_sast_semgrep_cron.yml index da5d60a89..7be416042 100644 --- a/.github/workflows/sec_sast_semgrep_cron.yml +++ b/.github/workflows/sec_sast_semgrep_cron.yml @@ -29,7 +29,8 @@ jobs: semgrep \ --sarif --output report.sarif \ --metrics=off \ - --config="p/default" + --config="p/default" \ + --exclude-rule="yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag" # step 3 - name: save report as pipeline artifact diff --git a/.github/workflows/sec_sast_semgrep_pull.yml b/.github/workflows/sec_sast_semgrep_pull.yml index 3783fae41..392e8f136 100644 --- a/.github/workflows/sec_sast_semgrep_pull.yml +++ b/.github/workflows/sec_sast_semgrep_pull.yml @@ -28,4 +28,5 @@ jobs: --error \ --metrics=off \ --baseline-commit ${{ github.event.pull_request.base.sha }} \ - --config="p/default" + --config="p/default" \ + --exclude-rule="yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag" diff --git a/.semgrepignore b/.semgrepignore index c42de5345..15f95bd13 100644 --- a/.semgrepignore +++ b/.semgrepignore @@ -1,7 +1,3 @@ -.github/workflows/main_matrix.yml -.github/workflows/build_windows_bin.yml -.github/workflows/package_winget.yml -src/mesh/compression/unishox2.cpp # Emscripten/WebUSB browser glue for the wasm node — not part of the firmware # binary or its security surface. The format-string rule false-positives on its # benign retry/diagnostic console logs.