Skip to content

ci(security): Security Scanning is red on master for three untracked reasons — gofmt, gosec SARIF, deprecated CodeQL v2 #818

Description

@alex-dembele

Problem

A maintainer or buyer who looks at CI sees the Security Scanning workflow (.github/workflows/security.yml) red on every master push. The runs for 6a8c964, cefe3af and a70639e on 2026-09-25 all failed. A permanently red security gate means nothing: a real finding would not stand out.

Five jobs fail. Two are already tracked: DAST (actions/upload-artifact@v3 rejected, #649) and License Compliance (action go-mod-outdated/go-mod-outdated-action no longer exists, #774). The other three had no issue:

Job Cause (log from run 36127603162, PR #817)
Code Quality Analysis gofmt -s -l backend lists 14 files, for example internal/handler/risk_handler.go, pkg/cache/pool.go, internal/domain/telemetry.go
Go Security Scan securego/gosec@master writes -fmt json, but codeql-action/upload-sarif expects SARIF (instance requires property "version", "runs")
SAST Security Analysis (Semgrep) github/codeql-action/upload-sarif@v2 is deprecated and fails, and semgrep.sarif is never produced (Path does not exist)

Found while checking PR #817, which only changes docs/DECISIONS.md.

Acceptance criteria

  1. gofmt -s -l backend returns nothing: the 14 files are formatted, with no logic change, in a commit of their own.
  2. gosec writes SARIF (-fmt sarif) and is pinned to a release by SHA, not @master. The upload succeeds.
  3. Every github/codeql-action/* action moves to v3, pinned by SHA. Semgrep produces semgrep.sarif (current semgrep ci --sarif invocation) or the job is replaced; the PR records which.
  4. actions/checkout@v3 and actions/setup-go@v4 in this workflow are updated (Node 20 deprecation warning).
  5. The Security Scanning workflow is green on the PR and on master after the merge, together with DAST gate never runs: security.yml uses the rejected actions/upload-artifact@v3 #649 and ci(security): the license compliance job has never run, and would pass on anything #774. The run link is pasted here.

Definition of Done

Security Scanning is green on master and fails only on a real finding.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:infraDocker, K8s, CIarea:qualityQuality, reliability and release readinessarea:securityCybersecurity and threat intelligencepriority:P1Highpriority:P1-highBlocks a milestonestatus:readyMeets the ready definitiontier:0-trustTrust: security, isolation, evidence integritytype:bugSomething is broken

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions