Skip to content

ci: pin semgrep to 1.175.0 and screen its install - #50

Merged
hironow merged 1 commit into
mainfrom
ci/semgrep-pin
Sep 4, 2026
Merged

hironow merged 1 commit into
mainfrom
ci/semgrep-pin

Conversation

@hironow

@hironow hironow commented Sep 4, 2026 •

Copy link
Copy Markdown
Owner

Owner decision Q44(a), revised to 1.175.0 after the version check. One ci:
commit.

Why

pipx install semgrep took whatever was newest at run time. semgrep gates
merges, so a release could turn CI red on a commit that changed nothing — a new
or widened rule needs no commit behind it to start failing.

The job also gains the Takumi Guard step every other install-bearing job has,
placed before uv tool install so the install resolves through the screened
index rather than PyPI. This was the last unscreened install in the repo.

Why 1.175.0 and not the newest

1.176.0 would have been a version the project's own supply-chain rules reject,
on two independent counts:

1.176.0 1.175.0
On the screened index no — proxy carries up to 1.175.0 yes
Older than the seven-day exclude-newer window no — published 2026-09-01 yes — 2026-08-26

With Takumi Guard now in this job, pinning 1.176.0 would not merely have been
inconsistent — it would have failed outright. The step comment records the rule
for whoever raises it next: pick a version the proxy carries and that is older
than the window.

CI evidence

Takumi Guard configures the job's index:

Route installs through Takumi Guard
  registry-url: https://pypi.flatt.tech
  set-index-url: true

and the install resolves through it:

Run uv tool install semgrep==1.175.0
Resolved 66 packages in 8.33s
Installed 66 packages in 30ms
 + semgrep==1.175.0

Local verification

Run against semgrep 1.175.0 — the machine's own semgrep is 1.162.0 and was
left untouched.

Check Result
just semgrep-test 3/3 rules pass
just semgrep 0 findings, 3 rules, 21 targets
just ci pass
prek check-yaml pass
Actions SHA-pinned 11/11

Worth noting how that verification resolved: with no index or cutoff
override
, through a uv configured for the screened index and the seven-day
window. Getting 1.175.0 that way is itself the proof it satisfies both rules —
the same command could not produce 1.176.0.

Job names unchanged; the protect ruleset matches its eleven required checks by
name.

Docs

docs/release.md: CI pins semgrep to 1.175.0 and installs it through the
screened index; Dependabot does not track it, so raising the version is a
deliberate edit — pick one the proxy carries and that is older than the
seven-day window. docs/handover.md untouched.

🤖 Generated with Claude Code

https://claude.ai/code/session_01LXPmm8VuMHBjo4Q6k7tRtq

`pipx install semgrep` took whatever was newest at run time, so a semgrep
release could turn CI red on a commit that changed nothing -- a new or widened
rule needs no commit behind it to start failing. `uv tool install
semgrep==1.175.0` makes the version a decision instead of a coincidence.

The job also gains the Takumi Guard step every other install-bearing job has,
placed before `uv tool install` so the install resolves through the screened
index rather than PyPI. This job was the last unscreened install in the repo.

1.175.0 rather than the newest: it is on the proxy, and it is older than the
seven-day `exclude-newer` window the project applies everywhere else. 1.176.0
satisfied neither -- the proxy carries only up to 1.175.0, and 1.176.0 shipped
2026-09-01, inside the window -- so pinning it would have meant a version the
project's own supply-chain rules reject. The comment on the step says so, for
whoever raises it next.

setup-uv is added to the job, SHA-pinned to the same v10.0.1 and uv 0.11.17 the
other jobs use. Job names are unchanged.

Verified at 1.175.0: `just semgrep-test` passes 3/3 rules, `just semgrep`
reports 0 findings over 21 targets, and `just ci` is green. The verification
resolved 1.175.0 with no index or cutoff override, through a uv configured for
the screened index and the seven-day window -- which is itself the proof the
version satisfies both rules.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LXPmm8VuMHBjo4Q6k7tRtq
@hironow hironow changed the title ci: pin semgrep to 1.176.0 ci: pin semgrep to 1.175.0 and screen its install Sep 4, 2026
@hironow
hironow merged commit a07b512 into main Sep 4, 2026
15 checks passed
@hironow
hironow deleted the ci/semgrep-pin branch September 4, 2026 11:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant