Skip to content

Fix catalog scanner gate to enforce the score threshold - #583

Draft
theisegoria wants to merge 1 commit into
hashgraph-online:mainfrom
theisegoria:fix-catalog-score-gate
Draft

theisegoria wants to merge 1 commit into
hashgraph-online:mainfrom
theisegoria:fix-catalog-score-gate

Conversation

@theisegoria

Copy link
Copy Markdown
Contributor

A centralized scan scoring 85/100 currently fails because both catalog workflows also set fail_on_severity: high. This implements the maintainer's requested score-based gate: keep min_score: 80 and use the pinned scanner action's supported fail_on_severity: none setting. Findings remain visible, and unsuccessful or unavailable scans still block the contribution check.

Updates both scan workflows, contributor documentation, and check messaging. Corrects two existing tests that expected failed or missing centralized scans to pass, adds failure-path coverage, and includes the validator test module in CI. Scanner/action pins, permissions, trusted default-branch checkout, and publisher success requirements are unchanged.

Validation:

  • All 50 repository unit tests pass (python -m unittest tests/test-*.py), as do alphabetical validation, contribution validation against origin/main, and git diff --check.
  • Local probes using the pinned plugin-scanner==3.0.123 action runner and each workflow's inputs: scores 0/79 fail; 80/85/100 pass with 12 high findings retained. Scanner exceptions propagate; the sweep still rejects discovery, catalog-validation, and scan failures.
  • Fresh offline scan of Game Development Studio commit 3a9cd3f08f970ded8db71d31e71ac665f313f9cd: exit 0, score 85/100, 0 critical / 12 high / 0 medium / 2 low / 2 info. Findings match the previous published report exactly. This was local validation, not a completed upstream Actions run.

For #562, a maintainer needs to apply this change to the default branch, run a fresh Sweep Open Plugin Contributions dispatch for PR 562, and authorize the pending contribution workflows. The listing branch will also need the updated base before its pull_request scan can use the corrected configuration. This PR does not merge or approve the listing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant