Skip to content

Remove SARIF generation and upload and rebuild assets - #48

Merged
JosephMaynard merged 1 commit into
masterfrom
fix/remove-sarif-upload
May 14, 2026
Merged

JosephMaynard merged 1 commit into
masterfrom
fix/remove-sarif-upload

Conversation

@JosephMaynard

@JosephMaynard JosephMaynard commented May 14, 2026 •

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

  • Chores
    • Simplified OpenSSF Scorecard workflow configuration to streamline security scanning processes.

@coderabbitai

coderabbitai Bot commented May 14, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: b11d7916-8acf-4a2d-989e-61e854e5d60d

📥 Commits

Reviewing files that changed from the base of the PR and between f0a132f and 1656fc4.

⛔ Files ignored due to path filters (3)
  • dist/report-assets.js is excluded by !**/dist/**
  • report-ui/dist/report.css is excluded by !**/dist/**
  • report-ui/dist/report.iife.js is excluded by !**/dist/**
📒 Files selected for processing (2)
  • .github/workflows/scorecard.yml
  • src/report-assets.ts
💤 Files with no reviewable changes (1)
  • .github/workflows/scorecard.yml

📝 Walkthrough

Walkthrough

The OpenSSF Scorecard GitHub Actions workflow configuration was simplified to use the Scorecard action's native publish_results feature directly, removing the separate SARIF upload step and its associated file/format parameters.

Changes

Scorecard Workflow Publishing Simplification

Layer / File(s) Summary
Scorecard action and SARIF upload consolidation
.github/workflows/scorecard.yml
The Scorecard action's with configuration now uses only publish_results: true, removing the prior results_file and results_format parameters. The redundant downstream "Upload SARIF results" step that invoked github/codeql-action/upload-sarif is also removed, relying instead on the Scorecard action's built-in publishing behavior.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

  • JosephMaynard/dependency-radar#45: Modifies the same .github/workflows/scorecard.yml file to configure OpenSSF Scorecard in the workflow (initial setup versus this simplification of publishing behavior).

Poem

🐰 A rabbit hops through workflows clean,
One step removed where steps had been,
The Scorecard now publishes with pride,
No manual uploads needed—simplified! ✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main change: removing SARIF generation/upload configuration from the GitHub workflow. However, it mentions 'rebuild assets' which is not evident in the file summary provided.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/remove-sarif-upload

Comment @coderabbitai help to get the list of available commands and usage tips.

@JosephMaynard
JosephMaynard merged commit 640c531 into master May 14, 2026
5 checks passed
@JosephMaynard
JosephMaynard deleted the fix/remove-sarif-upload branch May 14, 2026 22:54
@JosephMaynard
JosephMaynard restored the fix/remove-sarif-upload branch May 14, 2026 23:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant