ci(semgrep): install via runner python3/pip, drop container + setup-python
CI / api-client-drift (push) Failing after 30s
CI / frontend (push) Successful in 1m51s
CI / storybook-a11y (push) Successful in 4m50s
CI / backend (push) Successful in 1m29s
CI / e2e (push) Successful in 3m0s
CI / semgrep (push) Failing after 29s

The container: approach failed — this act_runner times out pulling its base runner
image (docker.gitea.com/runner-images:ubuntu-latest, IPv6) for container jobs. And
the earlier setup-python step failed downloading Python. Both avoided: run on the
plain ubuntu-latest runner and install semgrep with the preinstalled python3/pip
(`python3 -m pip install --break-system-packages semgrep`; --break-system-packages
survives PEP-668, pip puts semgrep on PATH). Verified in a clean python:3.12
container that pip install lands `semgrep` on PATH and the scan runs. Still
report-only; WP-30 tracks the flip to --error.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
eho
2026-07-22 10:10:57 +02:00
co-authored by Claude Opus 4.8
parent b34cc2ba3b
commit 9b2a878933
+5 -5
View File
@@ -112,17 +112,17 @@ jobs:
# SAST for both sides — replaces CodeQL, which is GitHub-only (its analyze step uploads
# SARIF to GitHub's code-scanning API) and can't run on this Gitea instance. Semgrep OSS
# is a plain CLI: no account, no external platform API. Findings print in the job log.
# Runs in the official Semgrep image (semgrep preinstalled) — the setup-python + pip
# approach failed on this runner. Fully-qualified image name so short-name resolution
# works regardless of the container engine (Docker or podman).
# Installed via the runner's preinstalled python3/pip — NOT `setup-python` (its Python
# download failed on this runner) and NOT a job `container:` (this act_runner times out
# pulling the base runner image for container jobs). `--break-system-packages` survives
# PEP-668; pip drops `semgrep` on PATH. Verified locally: install + scan run clean.
# ponytail: report-only for now (no `--error`, so the job stays green while the initial
# findings are triaged); flip to `--error` to make it a blocking gate. See WP-30.
runs-on: ubuntu-latest
timeout-minutes: 15
container:
image: docker.io/semgrep/semgrep
steps:
- uses: actions/checkout@v4
- run: python3 -m pip install --break-system-packages semgrep
# p/default = curated cross-language security (covers JS/TS); p/csharp = the backend.
# Anonymous registry fetch; --metrics=off disables telemetry (not `auto`, which uploads
# project metadata).