• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / amber / 32868250777
92%

Build:
DEFAULT BRANCH: main
Ran 25 Aug 2026 03:53PM UTC
Jobs 1
Files 31
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

25 Aug 2026 03:50PM UTC coverage: 92.879%. Remained the same
32868250777

push

github

web-flow
chore(ci): add Semgrep gate, pin actions to SHAs, add Dependabot cooldown (#61)

* chore(ci): add Semgrep gate, pin actions to SHAs, add Dependabot cooldown

Closes the three infrastructure findings from the 2026-08-25 Semgrep export
that were real, and stops the scan depending on someone running it by hand.

Semgrep runs as a gate on pull requests and advisory on main. `semgrep ci` is
diff-aware on a PR, so it fails only on findings that PR introduces — the same
bargain PHPStan's baseline strikes, with the platform holding the existing
state rather than a committed file. On main it scans in full and uploads;
continue-on-error keeps that off the release path, because a merge is the
release and the 25 findings already open must not be able to freeze one.

It is a run: step, not semgrep/semgrep-action. uses: steps ignore
defaults.run.working-directory, and this job has six repos checked out side by
side, so an action would scan all of them and file Unity's and Scrutiny's
findings against this repo — where they would never dedupe against those
repos' own scans, and a merge into one of them could fail an unrelated PR
here. Running from inside amber/ scopes the scan to this git repo. It also
keeps a third-party action out of the security scanning, which is the shape
the trivy-action compromise took.

The step skips when SEMGREP_APP_TOKEN is absent rather than falling back to
the OSS ruleset: two of this repo's findings are pro rules, and a scan that
silently checks less while reporting green is worse than no scan.

All 16 action refs are pinned to commit SHAs with the version in a trailing
comment, which is the form Dependabot maintains. Both Dependabot ecosystems
get a 7-day cooldown.

Refs: 16x github-actions-mutable-action-tag, 2x dependabot-missing-cooldown.

* fix(ci): gate the release on Semgrep's main scan too

The main-branch scan ran with continue-on-error, so a blocking finding left
the ci job green and release published anyway. That bought an un... (continued)

3678 of 3960 relevant lines covered (92.88%)

3.89 hits per line

Jobs
ID Job ID Ran Files Coverage
1 32868250777.1 25 Aug 2026 03:53PM UTC 31
92.88
GitHub Action Run
Source Files on build 32868250777
  • Tree
  • List 31
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #32868250777
  • 00029a6a on github
  • Prev Build on main (#32069061325)
  • Next Build on main (#32901221584)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc