From 5db6d40874c72b2c9dd70ea93b831ed11123f445 Mon Sep 17 00:00:00 2001 From: teknium1 <127238744+teknium1@users.noreply.github.com> Date: Mon, 14 Sep 2026 19:15:00 -0700 Subject: [PATCH] ci: stop the advisory OSV scan from gating merges osv-scanner.yml documents itself as detection-only (fail-on-vuln: false, findings land in the Security tab) yet all-checks-pass listed it in needs, so any failure result blocked the merge. In practice the failures are not vulnerabilities: the "Upload to code-scanning" step hits GitHub's per-installation API rate limit whenever several PRs run at once, and a merge train of catalog entries went red on it across the board. The scan still runs on every PR and weekly on main; it just reports instead of gating. --- .github/workflows/ci.yaml | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index aaa8da0386..1d4c3638cd 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -250,7 +250,11 @@ jobs: - profile-artifact-check - supply-chain - review-labels - - osv-scanner + # osv-scanner is deliberately NOT a dependency: osv-scanner.yml is + # detection-only (fail-on-vuln: false, findings go to the Security tab) + # and its SARIF upload trips GitHub's per-installation API rate limit + # during merge trains, which turned an advisory scan into a merge + # blocker for whole batches of unrelated PRs. # The image build runs in its own workflow (docker.yml) and reports # its own check. It was never required here, because it is too slow # to block a merge. A separate run also stops it from holding this