Skip to content

Improvements to CI check flagging sensitive data flows - #9893

Merged
scholtzan merged 2 commits into
mainfrom
sensitive-data-flow-improvements
Sep 18, 2026
Merged

scholtzan merged 2 commits into
mainfrom
sensitive-data-flow-improvements

Conversation

@scholtzan

Copy link
Copy Markdown
Contributor

Description

Fixes the "Flag sensitive data flows" check failing the build when it had nothing to report . The step now always exits 0.

Also retracts stale advisories: when a push clears the flow, the check deletes its earlier comment and withdraws its own dataplatform-wg review request.

Related Tickets & Documents

Reviewer, please follow this checklist

@scholtzan
scholtzan requested a review from a team as a code owner September 18, 2026 16:36

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changes the Flag sensitive data flows step in .github/workflows/build.yml so it no longer propagates the sensitivity CLI's exit code, moves the any_changed check from a step-level if into the script, paginates the marker-comment lookup, writes findings to $GITHUB_STEP_SUMMARY, adds a retraction path that deletes the advisory comment and withdraws the dataplatform-wg review request when a push clears the flow, and adds an explanation of unresolved sources to the comment body.

Comments are workflow-only, so nothing here touches SQL conventions or schemas from the reviewer checklist. My findings center on the new retraction path: how it interacts with CODEOWNERS-driven review requests, and the job-level gate that prevents it from running in the revert case it's meant to handle. Verified against CODEOWNERS, the decide-runs job's validate-sql computation, and bigquery_etl/data_governance/cli.py (SENSITIVITY_UNGATED_EXIT_CODE = 2).

Comment thread .github/workflows/build.yml Outdated
Comment thread .github/workflows/build.yml Outdated
Comment thread .github/workflows/build.yml Outdated
@scholtzan

This comment has been minimized.

@scholtzan

Copy link
Copy Markdown
Contributor Author

Integration report

@scholtzan
scholtzan added this pull request to the merge queue Sep 18, 2026
Merged via the queue into main with commit ec6aa1a Sep 18, 2026
31 checks passed
@scholtzan
scholtzan deleted the sensitive-data-flow-improvements branch September 18, 2026 17:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants