Skip to content

ci: remove the daily SCM configuration check workflow - #3522

Merged
javirln merged 1 commit into
mainfrom
ci/remove-scm-configuration-check-workflow
Oct 5, 2026
Merged

javirln merged 1 commit into
mainfrom
ci/remove-scm-configuration-check-workflow

Conversation

@javirln

@javirln javirln commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

This PR removes the Daily SCM Configuration Check GitHub Actions workflow.

The SCM configuration check for this repository moves to the managed check that the Chainloop platform runs on a schedule. The platform uses its own GitHub App installation token. This token can read branch protection and the repository security settings.

Since #3260, the workflow token has only contents: read and metadata: read. The gatherer needs administration: read to read branch protection. Without it, the check reported that main has no protection rules, and the branch protection, code review, commit signing and patch management policies failed.

After this PR merges, the CHAINLOOP_GATHERER_APP_ID variable and the GATHERER_APP_PRIVATE_KEY secret are not used. You can remove them.

Related to https://linear.app/chainloop/issue/PFM-7577

This change was made with the assistance of Claude Code.

Review in cubic

The SCM configuration check for this repository moves to the managed
check that the Chainloop platform runs. The platform uses its own GitHub
App installation token, which can read branch protection and repository
security settings.

The GitHub Actions job used a token with only contents and metadata read
permissions. With that token the gatherer cannot read branch protection,
so the check reported that main has no protection rules.

Assisted-by: Claude Code
Signed-off-by: Javier Rodriguez <javier@chainloop.dev>
@chainloop-platform

chainloop-platform Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

AI Session Checks — ⚠️ no AI session found

Missing AI Coding Sessions

This organization requires every PR to be backed by a Chainloop Trace AI coding session, and none was found for this one.

Please make sure the AI coding session evidence has been sent by the Chainloop CLI, or add the skip-ai-session label to this PR to bypass this check.

Learn more about Chainloop Trace.


Security Checks

⏭️ 6 scans not applied

Scan Reason
secret-scan no files changed
vulnerability-scan no manifest/lockfile changed
github-actions-scan no workflow files changed
sast-scan no files changed
iac-scan no IaC files changed
security-context no files changed

PR validation — ✅ 3 passing

Status Policy Material Messages
✅ Passed pr-description-required pr-info -
✅ Passed pr-user-story-linked pr-info -
✅ Passed pr-min-approvals pr-info -

View attestation ↗


Powered by Chainloop and Chainloop Trace

@javirln
javirln requested a review from a team October 5, 2026 11:51
@javirln
javirln marked this pull request as ready for review October 5, 2026 11:52

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Re-trigger cubic

@javirln
javirln merged commit 1d8c028 into main Oct 5, 2026
16 of 17 checks passed
@javirln
javirln deleted the ci/remove-scm-configuration-check-workflow branch October 5, 2026 12:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants