feat(tcfeed): do not offer a scanner to a repository that has one - #129
Merged
Merged
Conversation
"Thanks but we already have trufflehog, codeql, cubic, vet and a linter." A survey of the repositories with open requests found ten of thirty-seven already running a scanner in-repo — CodeQL, semgrep, bandit. Better than a quarter of the batch was spent asking people who had the ground covered, and every one of those is a decline nobody needed to write. Checked by file contents, not file names. Several hide it in a ci.yml that says nothing about it: inspektor-gadget runs CodeQL and semgrep out of files called neither. The list is deliberately narrow — only tools that overlap what `scan` actually does, which is secrets and code-level patterns. Left off on purpose: dependabot updates dependencies; it does not read the code zizmor audits the workflows, not the application osv-scanner advisories against a lockfile, a different question Including those would have skipped konifer and reth, which have no code scanning at all and are exactly who this is for. Verified both still get asked. What it cannot see is a GitHub App. TruffleHog's hosted product, cubic and Snyk's app leave no workflow file, and the maintainer quoted above runs a repository whose workflows mention none of them. This removes obvious waste; it is not a guarantee and must not be described as one. TCFEED_SKIP_SCANNED=0 asks anyway. Verified end to end: expressjs/express skips with "already scans with CodeQL", and asks normally with the escape set. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
ThreatCrush Security Scan67 finding(s) HIGH/CRITICAL: 11 | MEDIUM: 55 | LOW: 1
…and 17 more. Full results in the Security tab. Snippets are redacted; ThreatCrush never prints matched credential material. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A survey of the 37 repositories with open requests found 10 already running a scanner in-repo — CodeQL, semgrep, bandit. Better than a quarter of the batch was spent asking people who had the ground covered, and every one of those is a decline nobody needed to write.
By contents, not file names
Several hide it in a
ci.ymlthat says nothing about it.inspektor-gadgetruns CodeQL and semgrep out of files called neither.A deliberately narrow list
Only tools that overlap what
scanactually does — secrets and code-level patterns. Left off on purpose:dependabotzizmorosv-scannerIncluding those would have skipped
dmaiken/koniferandparadigmxyz/reth, which have no code scanning at all and are exactly who this is for. Verified both still get asked.What it cannot see
GitHub Apps. TruffleHog hosted, cubic and Snyk App leave no workflow file — and the maintainer quoted above runs a repository whose workflows mention none of their stack. This removes obvious waste; it is not a guarantee and must not be described as one.
TCFEED_SKIP_SCANNED=0asks anyway.Verified
tsc --strict --noEmitclean. Detector against known repos:End to end through
prTarget, both directions:🤖 Generated with Claude Code