Skip to content

docs: disable Code Security scanning on private frmscoe rules - #124

Merged
KyleVorster7 merged 1 commit into
devfrom
docs/disable-private-code-scanning
Aug 19, 2026
Merged

docs: disable Code Security scanning on private frmscoe rules#124
KyleVorster7 merged 1 commit into
devfrom
docs/disable-private-code-scanning

Conversation

@KyleVorster7

@KyleVorster7 KyleVorster7 commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Document the decision in the README: no dedicated billable Code Security scanning (njsscan / Scorecard) on private frmscoe rule repos.
  • Keep that scanning on public tazama-lf/rule-901 and rule-902; fixes propagate through the normal central-workflow path.
  • Stop syncing njsscan.yml and scorecard.yml to the 33 private rules, and delete leftovers on sync.

Why

SARIF upload on private repos needs paid GitHub Code Security. Enablement is locked on these private rules, so those jobs fail without a usable dashboard. Public reference rules get Code Security for free.

This follows the agreed approach: document in frmscoe/workflows, then turn off scanning on the private repos.

Test plan

  • README decision section is clear
  • After merge, sync-workflows no longer copies njsscan/scorecard
  • Sync removes leftover njsscan.yml / scorecard.yml from a sample rule repo

Signed-off-by: KyleVorster7 <108583489+KyleVorster7@users.noreply.github.com>
@KyleVorster7
KyleVorster7 requested review from a team as code owners August 13, 2026 19:37
@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Aug 13, 2026
@KyleVorster7
KyleVorster7 merged commit 0928e90 into dev Aug 19, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants