Skip to content

Conversation

@sarasvoss
Copy link
Contributor

PR Summary

Jira: https://opensesame.atlassian.net/browse/CORE-5315

Description of Changes

  • created new reusable action for upserting PR comment
  • refactored run semgrep workflow for maintainability

Versioning

⚠️ Components in this repo are used by multiple repos and teams. Breaking changes to non-versioned components are high-risk. Always apply correct versioning to versioned components to ensure safe, controlled updates.

Versioned components live under ./github/actions

Does this PR modify a versioned component?

  • No — label this PR with version:untracked
  • Yes
    • Add a version label: version:<component-name>/X.Y.Z
    • Ensure the component’s CHANGELOG.md includes a ## X.Y.Z entry
    • Use version:untracked only if changes do not alter behavior, inputs, or outputs

If version labels are incorrect or missing, automated version validation will fail and block merge.

Dependencies of PR

N/A

Testing

semgrep workflow runs on PR of this repo so fully tested before merge

@github-actions
Copy link

github-actions bot commented Dec 23, 2025

✅ Semgrep Security Scan Passed

Scan Config

  • Rules: p/ci p/security-audit p/javascript
  • Targets: ./*.js ./*.mjs ./*.json scripts/ .github/actions/
  • Scan mode: diff
  • Baseline: origin/main
  • Fail level: error
  • Extra args: n/a

Findings

🎉 No security issues found!

View run
🤖 Powered by Semgrep + reviewdog

@sarasvoss sarasvoss force-pushed the run_semgrep_wf branch 3 times, most recently from 40d8783 to a7002db Compare December 23, 2025 23:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants