Skip to content

feat(tcfeed): do not offer a scanner to a repository that has one - #129

Merged
ralyodio merged 1 commit into
masterfrom
worktree-tcfeed-skip-covered
Aug 13, 2026
Merged

ralyodio merged 1 commit into
masterfrom
worktree-tcfeed-skip-covered

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Thanks but we already have trufflehog, codeql, cubic, vet and a linter.

A survey of the 37 repositories with open requests found 10 already running a scanner in-repo — CodeQL, semgrep, bandit. Better than a quarter of the batch was spent asking people who had the ground covered, and every one of those is a decline nobody needed to write.

By contents, not file names

Several hide it in a ci.yml that says nothing about it. inspektor-gadget runs CodeQL and semgrep out of files called neither.

A deliberately narrow list

Only tools that overlap what scan actually does — secrets and code-level patterns. Left off on purpose:

tool why not
dependabot updates dependencies; it does not read the code
zizmor audits the workflows, not the application
osv-scanner advisories against a lockfile — a different question

Including those would have skipped dmaiken/konifer and paradigmxyz/reth, which have no code scanning at all and are exactly who this is for. Verified both still get asked.

What it cannot see

GitHub Apps. TruffleHog hosted, cubic and Snyk App leave no workflow file — and the maintainer quoted above runs a repository whose workflows mention none of their stack. This removes obvious waste; it is not a guarantee and must not be described as one. TCFEED_SKIP_SCANNED=0 asks anyway.

Verified

tsc --strict --noEmit clean. Detector against known repos:

inspektor-gadget/inspektor-gadget -> CodeQL and Semgrep
stamparm/maltrail             -> CodeQL and Bandit
trevorwang/retrofit.dart      -> CodeQL
dmaiken/konifer               -> not covered — would ask   (dependabot only)
paradigmxyz/reth              -> not covered — would ask   (zizmor only)

End to end through prTarget, both directions:

$ tcfeed pr expressjs/express --dry-run
· expressjs/express — skipped: already scans with CodeQL

$ TCFEED_SKIP_SCANNED=0 tcfeed pr expressjs/express --dry-run
· expressjs/express — dry run

🤖 Generated with Claude Code

"Thanks but we already have trufflehog, codeql, cubic, vet and a linter."

A survey of the repositories with open requests found ten of thirty-seven
already running a scanner in-repo — CodeQL, semgrep, bandit. Better than a
quarter of the batch was spent asking people who had the ground covered,
and every one of those is a decline nobody needed to write.

Checked by file contents, not file names. Several hide it in a ci.yml that
says nothing about it: inspektor-gadget runs CodeQL and semgrep out of
files called neither.

The list is deliberately narrow — only tools that overlap what `scan`
actually does, which is secrets and code-level patterns. Left off on
purpose:

  dependabot   updates dependencies; it does not read the code
  zizmor       audits the workflows, not the application
  osv-scanner  advisories against a lockfile, a different question

Including those would have skipped konifer and reth, which have no code
scanning at all and are exactly who this is for. Verified both still get
asked.

What it cannot see is a GitHub App. TruffleHog's hosted product, cubic and
Snyk's app leave no workflow file, and the maintainer quoted above runs a
repository whose workflows mention none of them. This removes obvious
waste; it is not a guarantee and must not be described as one.
TCFEED_SKIP_SCANNED=0 asks anyway.

Verified end to end: expressjs/express skips with "already scans with
CodeQL", and asks normally with the escape set.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

67 finding(s)

HIGH/CRITICAL: 11 | MEDIUM: 55 | LOW: 1

Severity Rule Location
HIGH secret-aws-access-key prd/0003-detect-hardcoded-secrets-before-they-are-committed-or-served.md:126
HIGH sh-eval-expansion .githooks/pre-commit:26
HIGH sh-remote-script-execution apps/web/public/install.sh:272
HIGH sh-remote-script-execution apps/web/public/install.sh:320
HIGH secret-generic-credential modules/spend-guard/config/example.conf.toml:13
HIGH secret-generic-credential modules/spend-guard/README.md:84
HIGH secret-generic-credential PRD.md:268
HIGH tls-verification-disabled prd/0004-find-dangerous-code-patterns-without-pretending-to-be-a-compiler.md:121
HIGH tls-verification-disabled prd/0004-find-dangerous-code-patterns-without-pretending-to-be-a-compiler.md:122
HIGH sh-remote-script-execution scripts/smoke-test.sh:46
HIGH sh-remote-script-execution scripts/smoke-test.sh:47
MEDIUM insecure-temp-file .githooks/commit-msg:16
MEDIUM insecure-temp-file .githooks/post-commit:20
MEDIUM js-shell-exec-interpolation apps/cli/src/commands/init.ts:70
MEDIUM js-shell-exec-interpolation apps/cli/src/commands/init.ts:79
MEDIUM js-shell-exec-interpolation apps/cli/src/commands/service.ts:88
MEDIUM js-shell-exec-interpolation apps/cli/src/commands/service.ts:111
MEDIUM sql-template-interpolation apps/cli/src/core/state.ts:121
MEDIUM sql-template-interpolation apps/cli/src/core/state.ts:125
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:31
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:33
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:34
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:35
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:36
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:43
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:49
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:56
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:63
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:82
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:84
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:85
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:93
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:98
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:105
MEDIUM js-shell-exec-interpolation apps/cli/src/daemon/firewall/adapters.ts:112
MEDIUM js-shell-exec-interpolation apps/cli/src/index.ts:419
MEDIUM js-unescaped-html-sink apps/web/src/app/about/page.tsx:180
MEDIUM js-unescaped-html-sink apps/web/src/app/about/page.tsx:184
MEDIUM js-open-redirect apps/web/src/app/auth/login/page.tsx:50
MEDIUM js-unescaped-html-sink apps/web/src/app/blog/[slug]/page.tsx:125
MEDIUM js-unescaped-html-sink apps/web/src/app/blog/[slug]/page.tsx:153
MEDIUM js-unescaped-html-sink apps/web/src/app/blog/[slug]/page.tsx:157
MEDIUM js-unescaped-html-sink apps/web/src/app/get-whitepaper/page.tsx:346
MEDIUM js-unescaped-html-sink apps/web/src/app/layout.tsx:211
MEDIUM js-unescaped-html-sink apps/web/src/app/layout.tsx:215
MEDIUM js-unescaped-html-sink apps/web/src/app/layout.tsx:219
MEDIUM js-unescaped-html-sink apps/web/src/app/page.tsx:120
MEDIUM js-unescaped-html-sink apps/web/src/app/store/[slug]/page.tsx:107
MEDIUM js-open-redirect apps/web/src/components/funding/FundingClient.tsx:97
MEDIUM manifest-install-lifecycle-script package.json:24

…and 17 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 1056265 into master Aug 13, 2026
11 checks passed
@ralyodio
ralyodio deleted the worktree-tcfeed-skip-covered branch August 13, 2026 15:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant