Repository navigation
Fix catalog scanner gate to enforce the score threshold - #583
Draft
theisegoria wants to merge 1 commit into
Draft
theisegoria wants to merge 1 commit into
theisegoria wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A centralized scan scoring 85/100 currently fails because both catalog workflows also set
fail_on_severity: high. This implements the maintainer's requested score-based gate: keepmin_score: 80and use the pinned scanner action's supportedfail_on_severity: nonesetting. Findings remain visible, and unsuccessful or unavailable scans still block the contribution check.Updates both scan workflows, contributor documentation, and check messaging. Corrects two existing tests that expected failed or missing centralized scans to pass, adds failure-path coverage, and includes the validator test module in CI. Scanner/action pins, permissions, trusted default-branch checkout, and publisher success requirements are unchanged.
Validation:
python -m unittest tests/test-*.py), as do alphabetical validation, contribution validation againstorigin/main, andgit diff --check.plugin-scanner==3.0.123action runner and each workflow's inputs: scores 0/79 fail; 80/85/100 pass with 12 high findings retained. Scanner exceptions propagate; the sweep still rejects discovery, catalog-validation, and scan failures.3a9cd3f08f970ded8db71d31e71ac665f313f9cd: exit 0, score 85/100, 0 critical / 12 high / 0 medium / 2 low / 2 info. Findings match the previous published report exactly. This was local validation, not a completed upstream Actions run.For #562, a maintainer needs to apply this change to the default branch, run a fresh
Sweep Open Plugin Contributionsdispatch for PR 562, and authorize the pending contribution workflows. The listing branch will also need the updated base before itspull_requestscan can use the corrected configuration. This PR does not merge or approve the listing.