Skip to content

ci(security): keep weekly osv-audit green, report via SARIF - #41

Merged
valandi merged 1 commit into
mainfrom
fix/osv-audit-status
Jul 27, 2026
Merged

ci(security): keep weekly osv-audit green, report via SARIF#41
valandi merged 1 commit into
mainfrom
fix/osv-audit-status

Conversation

@valandi

@valandi valandi commented Jul 27, 2026

Copy link
Copy Markdown
Collaborator

One-line follow-up from the security-setup final review: pass fail-on-vuln: false to the osv-audit reusable workflow call so the weekly run's status means the scan ran, not that the repo has zero findings (that signal lives in the Security tab). The PR gate osv-pr is unchanged and still fails on newly introduced vulnerabilities.

🤖 Generated with Claude Code

…he run

A scheduled job that is red whenever any vulnerability exists trains people
to ignore it and masks real scanner outages. Findings still land in the
Security tab; the PR gate (osv-pr) keeps its failing behavior.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@valandi
valandi merged commit 394a953 into main Jul 27, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant