Skip to content

Update Socket Basics job call path and migrate suppression config - #61

Merged
bradymholt merged 1 commit into
mainfrom
remove-legacy-socket-basics-config
Sep 1, 2026
Merged

Update Socket Basics job call path and migrate suppression config#61
bradymholt merged 1 commit into
mainfrom
remove-legacy-socket-basics-config

Conversation

@sgrammargs

Copy link
Copy Markdown
Contributor

Migrates this repo's Socket Basics CI scan to the new ynab-sast-scanner / ynab-sast-scanner-suppressions split — a public repo for the scanning mechanism, a private repo for suppression policy.

Changes to .github/workflows/socket-basics.yml:

  • uses: now points to ynab/ynab-sast-scanner/.github/workflows/socket-basics.yml@main
  • Added the SAST_SUPPRESSIONS_APP_PRIVATE_KEY secret
  • Removed a stale comment about shared-actions that no longer applies here

Also removes .socket-basics.json — its content now lives in ynab-sast-scanner-suppressions.

Points the CI workflow at ynab-sast-scanner instead of shared-actions, adds the
new App-token secret, and removes the legacy shared-actions caller comment.
Also removes .socket-basics.json now that suppressions are centralized.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@sgrammargs
sgrammargs marked this pull request as ready for review September 1, 2026 17:22
@sgrammargs
sgrammargs requested a review from grantcox September 1, 2026 17:38
@bradymholt
bradymholt merged commit 0ff81d6 into main Sep 1, 2026
6 checks passed
@bradymholt
bradymholt deleted the remove-legacy-socket-basics-config branch September 1, 2026 17:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants