You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A maintainer or buyer who looks at CI sees the Security Scanning workflow (.github/workflows/security.yml) red on every master push. The runs for 6a8c964, cefe3af and a70639e on 2026-09-25 all failed. A permanently red security gate means nothing: a real finding would not stand out.
Five jobs fail. Two are already tracked: DAST (actions/upload-artifact@v3 rejected, #649) and License Compliance (action go-mod-outdated/go-mod-outdated-action no longer exists, #774). The other three had no issue:
github/codeql-action/upload-sarif@v2 is deprecated and fails, and semgrep.sarif is never produced (Path does not exist)
Found while checking PR #817, which only changes docs/DECISIONS.md.
Acceptance criteria
gofmt -s -l backend returns nothing: the 14 files are formatted, with no logic change, in a commit of their own.
gosec writes SARIF (-fmt sarif) and is pinned to a release by SHA, not @master. The upload succeeds.
Every github/codeql-action/* action moves to v3, pinned by SHA. Semgrep produces semgrep.sarif (current semgrep ci --sarif invocation) or the job is replaced; the PR records which.
actions/checkout@v3 and actions/setup-go@v4 in this workflow are updated (Node 20 deprecation warning).
Problem
A maintainer or buyer who looks at CI sees the Security Scanning workflow (
.github/workflows/security.yml) red on everymasterpush. The runs for6a8c964,cefe3afanda70639eon 2026-09-25 all failed. A permanently red security gate means nothing: a real finding would not stand out.Five jobs fail. Two are already tracked: DAST (
actions/upload-artifact@v3rejected, #649) and License Compliance (actiongo-mod-outdated/go-mod-outdated-actionno longer exists, #774). The other three had no issue:gofmt -s -l backendlists 14 files, for exampleinternal/handler/risk_handler.go,pkg/cache/pool.go,internal/domain/telemetry.gosecurego/gosec@masterwrites-fmt json, butcodeql-action/upload-sarifexpects SARIF (instance requires property "version","runs")github/codeql-action/upload-sarif@v2is deprecated and fails, andsemgrep.sarifis never produced (Path does not exist)Found while checking PR #817, which only changes
docs/DECISIONS.md.Acceptance criteria
gofmt -s -l backendreturns nothing: the 14 files are formatted, with no logic change, in a commit of their own.-fmt sarif) and is pinned to a release by SHA, not@master. The upload succeeds.github/codeql-action/*action moves to v3, pinned by SHA. Semgrep producessemgrep.sarif(currentsemgrep ci --sarifinvocation) or the job is replaced; the PR records which.actions/checkout@v3andactions/setup-go@v4in this workflow are updated (Node 20 deprecation warning).masterafter the merge, together with DAST gate never runs: security.yml uses the rejected actions/upload-artifact@v3 #649 and ci(security): the license compliance job has never run, and would pass on anything #774. The run link is pasted here.Definition of Done
Security Scanning is green on
masterand fails only on a real finding.