Correct scanning workflow history and timing claims - #633
Merged
Conversation
View Full ReportLink Validation ReportGenerated: 2026-09-13T06:34:17 Validation results (unique URLs): 1009
Verification incomplete. Unresolved and unchecked results are advisory; they do not establish that a link is broken. See |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The scanning article described three incompatible job orders and still called the aggregate gate unimplemented. Inspection of the canonical gist's three dated revisions shows that its original November 2025 gate was an echo-only stub, while the August 18 and August 23, 2026 revisions check all three job results. The article now dates that correction, labels the old snippet as historical, and explains OSV-first followed by independent Grype/Trivy jobs. It also corrects the adjacent claim that every action is commit-pinned: checkout and SARIF upload still use version tags.
The performance table now labels its total as a sum of reported scanner durations and fixes the sum to 117 seconds. The 70% reduction is arithmetic on those listed figures, not a new benchmark. Historical timings, optimization savings and runner attribution are explicitly unverified because no retained timing evidence was found. No end-to-end workflow time is inferred from the dependency graph. The original post URL/date remain, with a September 13 correction and
lastUpdate.Validation: final production build passed; Astro check reported 0 errors and 0 warnings (7 existing hints); required pre-commit build passed. Source revisions, GitHub job semantics, scope and arithmetic are recorded in
docs/research/2026-09-13-scanning-vestigial-review.md. No gist or mirror was changed.Closes #632.