Skip to content

Conversation

@sarasvoss
Copy link
Contributor

@sarasvoss sarasvoss commented Dec 23, 2025

PR Summary

Jira: https://opensesame.atlassian.net/browse/CORE-5315

Description of Changes

  • created new reusable action for upserting PR comment
  • refactored run semgrep workflow for maintainability
  • setup repo to enforce version tags, Changelogs, and Readmes for reusable workflows

Versioning

⚠️ Components in this repo are used by multiple repos and teams. Breaking changes to non-versioned components are high-risk. Always apply correct versioning to versioned components to ensure safe, controlled updates.

Versioned components live under ./github/actions

Does this PR modify a versioned component?

  • No — label this PR with version:untracked
  • Yes
    • Add a version label: version:<component-name>/X.Y.Z
    • Ensure the component’s CHANGELOG.md includes a ## X.Y.Z entry
    • Use version:untracked only if changes do not alter behavior, inputs, or outputs

If version labels are incorrect or missing, automated version validation will fail and block merge.

Dependencies of PR

N/A

Testing

semgrep workflow runs on PR of this repo so fully tested before merge

@github-actions
Copy link

github-actions bot commented Dec 23, 2025

✅ Semgrep Security Scan Passed

🎉 No security issues found!

View run
🤖 Powered by Semgrep + reviewdog

@sarasvoss sarasvoss force-pushed the run_semgrep_wf branch 4 times, most recently from a7002db to 9af2395 Compare December 23, 2025 23:26
@sarasvoss sarasvoss force-pushed the run_semgrep_wf branch 3 times, most recently from 998e64a to 876e133 Compare January 12, 2026 17:45
@github-actions
Copy link

github-actions bot commented Jan 12, 2026

Tags

The following tags will be created on main after merge

🏷️ actions/upsert-pr-comment/1.0.0
🏷️ workflows/run_semgrep_scan/1.0.0

@sarasvoss sarasvoss force-pushed the run_semgrep_wf branch 3 times, most recently from 70839ff to aadc91d Compare January 12, 2026 17:59
@sarasvoss sarasvoss merged commit 79d5b97 into main Jan 12, 2026
4 checks passed
@sarasvoss sarasvoss deleted the run_semgrep_wf branch January 12, 2026 18:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants