Skip to content

Comments

Simpler sast#104

Draft
GrosQuildu wants to merge 8 commits intomainfrom
simpler-sast
Draft

Simpler sast#104
GrosQuildu wants to merge 8 commits intomainfrom
simpler-sast

Conversation

@GrosQuildu
Copy link
Contributor

@GrosQuildu GrosQuildu commented Feb 23, 2026

Both:

  • Removed triaging steps (skills return almost raw results)
  • Better descriptions with specific trigger language
  • Progressive disclosure pattern applied throughout (lean SKILL.md → references/ + workflows/)
  • Plugin version bumped

Semgrep:

  • SKILL.md slimmed down; content extracted to new references/scan-modes.md and workflows/scan-workflow.md
  • Removed the separate semgrep-triager agent — triage folded into the scanner agent
  • Scanner agent improved with language-scoping (--include flags) and better GitHub URL handling
  • Simplified merge_triaged_sarif.py

CodeQL:

  • Three workflow files heavily cut down (build-database, create-data-extensions, run-analysis)
  • Six new reference files extracted (build-fixes, extension-yaml-format, important-only-suite, macos-arm64e workaround, quality-assessment, run-all-suite, sarif-processing)

@GrosQuildu GrosQuildu marked this pull request as draft February 24, 2026 11:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant