Skip to content

Reduce recurring runner-guard static-analysis noise - #53398

Merged
pelikhan merged 9 commits into
mainfrom
copilot/static-analysis-report-2026-08-17
Aug 17, 2026
Merged

pelikhan merged 9 commits into
mainfrom
copilot/static-analysis-report-2026-08-17

Conversation

Copilot AI commented Aug 17, 2026 •

Copy link
Copy Markdown
Contributor

The static-analysis report flagged reviewed runner-guard findings that were not being recognized as safe: workflow_run actor allowlist gates for RGS-004, inline runner-guard:ignore suppressions for RGS-012, and step-output interpolation in two workflows.

  • Runner-guard authorization gates
    • Treat workflow_run jobs gated by workflow_dispatch plus an explicit actor allowlist as trusted activation gates.
    • Preserve findings unless the gated job is directly or transitively protected through needs.
if: >
  github.event.workflow_run.event == 'workflow_dispatch' &&
  contains(fromJSON('["trusted-user","trusted-bot"]'), github.event.workflow_run.actor.login)
  • Inline suppression handling

    • Honor local # runner-guard:ignore <RULE> comments near reported shell findings.
    • Covers generated lock-file line offsets where runner-guard reports the finding on a nearby setup or step-boundary line.
  • Workflow interpolation hardening

    • Moved step outputs into environment variables before use in run: blocks for:
      • error-message-lint.yml
      • windows-cli-integration.yml
  • Coverage

    • Added focused runner-guard tests for actor allowlist gates, suppression windows, unresolved files, and negative cases.
    • Regenerated required lock files so compiled workflows stay in sync.

Copilot AI linked an issue Aug 17, 2026 that may be closed by this pull request
Copilot AI and others added 6 commits August 17, 2026 14:12
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Update static analysis report for 2026-08-17 findings Reduce recurring runner-guard static-analysis noise Aug 17, 2026
Copilot AI requested a review from pelikhan August 17, 2026 14:30
@pelikhan
pelikhan marked this pull request as ready for review August 17, 2026 14:32
Copilot AI balanced review requested due to automatic review settings August 17, 2026 14:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Note

This error may be related to your runner configuration. You can now configure runners for Copilot code review separately from Copilot cloud agent by creating a copilot-code-review.yml file with your setup steps. Read the docs for details.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot please take another pass on this PR.

Please address these items, newest first:

  • Failed checks: impacted-go-tests, Unit tests (D-L).
  • Refresh the branch with the latest base changes if needed.
  • Run the pr-finisher skill and summarize the remaining maintainer-visible status.

Run: https://github.com/github/gh-aw/actions/runs/32043948991

Generated by 👨‍🍳 PR Sous Chef · gpt54 · 10.3 AIC · ⌖ 6.79 AIC · ⊞ 8.8K · ◷
Comment /souschef to run again

…is-report-2026-08-17

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Aug 17, 2026

Copy link
Copy Markdown
Contributor Author

@copilot please take another pass on this PR.

Please address these items, newest first:...

Addressed in ac9d01543c: merged the latest main, which contains the corrected daily regression audit contract test responsible for both failed jobs. The test now passes with and without CGO; lint, the full Go suite, workflow compilation, and the final change-scoped gate all pass locally. pr-finisher found no unresolved review threads; CI requires a maintainer re-trigger on the updated HEAD.

Copilot AI requested a review from gh-aw-bot August 17, 2026 16:31
@pelikhan
pelikhan merged commit 090e4a6 into main Aug 17, 2026
27 checks passed
@pelikhan
pelikhan deleted the copilot/static-analysis-report-2026-08-17 branch August 17, 2026 18:10
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.87.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[static-analysis] Report - 2026-08-17

4 participants