Skip to content

docs: sync the scanner wording from the template - #639

Merged
CybotTM merged 1 commit into
mainfrom
chore/sync-scanner-wording
Aug 2, 2026
Merged

docs: sync the scanner wording from the template#639
CybotTM merged 1 commit into
mainfrom
chore/sync-scanner-wording

Conversation

@CybotTM

@CybotTM CybotTM commented Aug 2, 2026

Copy link
Copy Markdown
Member

Picks up the wording correction from netresearch/.github#334 so this repo stays byte-identical to its template.

Three things the previous comments got wrong:

  • the header named betterleaks while the job and the reusable keep the historical gitleaks name — the name is deliberate (renaming breaks every caller that references the workflow path or pins the job in branch protection), and the header now says so
  • it called the last job a composer audit, but the reusable also runs an Opengrep SAST scanskip-opengrep defaults to false
  • the zizmor comment said the exemption covers "reusable workflows", while "netresearch/*": ref-pin matches any first-party uses:, composite actions included

Comments only. No job, permission or trigger changes, and the file was byte-identical to the previous template revision before this sync — anything that had drifted was left alone and reported instead.

Picks up netresearch/.github#334, which corrects three things a reviewer
raised repeatedly during the rollout: the header named betterleaks while the
job keeps the historical gitleaks name, it called the last job a composer
audit although the reusable also runs an Opengrep SAST scan by default, and
the zizmor comment said the exemption covers reusable workflows when the rule
matches any first-party uses, composite actions included.

Comments only — no job, permission or trigger changes.

Signed-off-by: Sebastian Mendel <github@sebastianmendel.de>
Copilot AI review requested due to automatic review settings August 2, 2026 13:47
@sonarqubecloud

sonarqubecloud Bot commented Aug 2, 2026

Copy link
Copy Markdown

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates zizmor configuration comments to match the upstream template wording, clarifying the scope of the first-party uses: exemption.

Changes:

  • Clarified that the netresearch/*: ref-pin policy applies to both reusable workflows and composite actions.
  • Expanded the rationale for tracking @main for first-party uses: to explain propagation benefits.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@codecov

codecov Bot commented Aug 2, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 70.89%. Comparing base (20effd0) to head (ea7db06).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #639   +/-   ##
=======================================
  Coverage   70.89%   70.89%           
=======================================
  Files          36       36           
  Lines        3567     3567           
=======================================
  Hits         2529     2529           
  Misses        876      876           
  Partials      162      162           
Flag Coverage Δ
e2e 58.99% <ø> (ø)
unittests 71.38% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated approval for maintainer PR

All automated quality gates passed. See SECURITY_CONTROLS.md for compensating controls.

@CybotTM
CybotTM added this pull request to the merge queue Aug 2, 2026
Merged via the queue into main with commit cbdccfa Aug 2, 2026
32 checks passed
@CybotTM
CybotTM deleted the chore/sync-scanner-wording branch August 2, 2026 15:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants