ci: add security scans
Metadata
Current evaluation
Closed without merging. The CI security scanning changes are being redirected to the canonical/starflow repository. A separate pull request will implement the updated starflow version instead.
Suggested action: —
No scores available.
Issue body
Adds two security scanning items:
1. A local dependencies security scan using trivy and osv
2. A (currently disabled) remote security scan using the Canonical security scanning API
Snap build error is fixed in #1916
This is the applications version. Compare to the libraries version at https://github.com/canonical/craft-platforms/pull/52
Once approval is provided here, I will upstream to Starbase and reproduce on our other applications.
NOTE: The Starbase version will be commented out below the libraries version, with a note that applications need to switch which version is commented.
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Closed without merging. The CI security scanning changes are being redirected to the canonical/starflow repository. A separate pull request will implement the updated starflow version instead. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Closed and superseded. The author redirected the CI security scan additions to canonical/starflow and will open a separate pull request there using the starflow version. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Closed without merging. Security scan configuration was redirected to the canonical/starflow repository. A separate pull request using the starflow version will be opened instead. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #573 ci: update usage of starflow security scanner | starbase | merged | Merged after two approvals and passing CI. Updated the python-scans job in policy.yaml to use new starflow security scanner options, adding an osv-scanner.toml placeholder and path exclusions. | |
| #2027 build(ci): use starflow for policy and security scans | charmcraft | merged | Merged update to the CI pipeline using starflow for policy and security scans. Approved by two reviewers, rebased on main, and reduced code by 12 lines across four files. | |
| #185 ci: fix security scanner | debcraft | merged | Merged a one-line change to fix the CI security scanner. Approved by one reviewer and passing all CI checks, the pull request was successfully integrated. | |
| #5068 ci: add security scan | snapcraft | merged | Merged following approval from two reviewers. The commit introduces a CI security scan, altering six files with 25 additions and 4 deletions to automate vulnerability checks. | |
| #859 ci: add security scanning job | craft-parts | merged | Merged a pull request adding a CI security scanning job. The change modified one file with 15 additions, received approval from two reviewers, and successfully integrated automated security checks into the project workflow. | |
| #861 ci: use starflow policy checker | craft-parts | closed | Closed without merging. The pull request to update CI to use the starflow policy checker was abandoned due to zero reviewer engagement, missing CI validation, and no subsequent activity. | |
| #200 ci: align policy OSV scan inputs with starbase | craft-grammar | merged | Merged. Updated CI workflow to align OSV security scan inputs with starbase, added a root config file, and excluded docs from scans. All CI checks passed. | |
| #494 ci: add security scanning job | craft-application | merged | Merged changes adding a CI security scanning job. Approved by two reviewers, the update introduces 15 lines to one file to automate pipeline security checks. | |
| #56 ci: add security scanning workflow | craft-grammar | merged | Merged adds a CI workflow for security scanning. Approved by two reviewers, the change introduces a single configuration file to automate pipeline security checks. | |
| #716 ci: add security scan workflow | rockcraft | merged | Merged to add a CI security scan workflow. Approved by two reviewers, the change modifies three files to automate security checks in the pipeline. |