Skip to content

Scorecard: publish to scorecard.dev only, not to code scanning - #26

Closed
emirb wants to merge 1 commit into
mainfrom
scorecard-no-sarif
Closed

Scorecard: publish to scorecard.dev only, not to code scanning#26
emirb wants to merge 1 commit into
mainfrom
scorecard-no-sarif

Conversation

@emirb

@emirb emirb commented Sep 3, 2026

Copy link
Copy Markdown
Owner

The SARIF upload put 31 policy alerts in the Security tab, 25 of them one
per action pinned to a major tag, which is a deliberate choice here and
would reopen on every Dependabot bump. The results stay on scorecard.dev
behind the badge and as a five-day artifact; code scanning is left to
CodeQL.

The SARIF upload put 31 policy alerts in the Security tab, 25 of them one
per action pinned to a major tag, which is a deliberate choice here and
would reopen on every Dependabot bump. The results stay on scorecard.dev
behind the badge and as a five-day artifact; code scanning is left to
CodeQL.
@emirb
emirb force-pushed the scorecard-no-sarif branch from 494f734 to fa0b85f Compare September 3, 2026 02:25
@emirb

emirb commented Sep 3, 2026

Copy link
Copy Markdown
Owner Author

Keeping the Scorecard results in code scanning; the findings get addressed instead.

@emirb emirb closed this Sep 3, 2026
@codecov

codecov Bot commented Sep 3, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 58.46%. Comparing base (7f2e3e3) to head (fa0b85f).

Additional details and impacted files
@@            Coverage Diff             @@
##             main      #26      +/-   ##
==========================================
+ Coverage   58.40%   58.46%   +0.05%     
==========================================
  Files          11       11              
  Lines        1690     1690              
==========================================
+ Hits          987      988       +1     
+ Misses        703      702       -1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@emirb
emirb deleted the scorecard-no-sarif branch September 4, 2026 16:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant