Skip to content

Improve SAST monorepo SARIF coverage gates#1530

Open
danyili2632 wants to merge 1 commit into
UnitOneAI:mainfrom
danyili2632:improve/sast-monorepo-sarif-coverage
Open

Improve SAST monorepo SARIF coverage gates#1530
danyili2632 wants to merge 1 commit into
UnitOneAI:mainfrom
danyili2632:improve/sast-monorepo-sarif-coverage

Conversation

@danyili2632
Copy link
Copy Markdown

Summary

  • add monorepo workspace coverage inventory requirements before scoring SAST maturity
  • add SARIF completeness gates for path/category metadata, generated/vendor LOC inflation, nested CodeQL extraction, and base-branch-only PR scans
  • extend CodeQL, CI, severity, and report output sections with per-component scan evidence

Bounty

Addresses #1527.

I have read and agree to the CONTRIBUTING.md bounty terms. Preferred payment method can be provided privately after maintainer acceptance.

Validation

  • git diff --check

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant