← Back to issue list

ci: add security scans

View original Github issue

Metadata

Project
charmcraft
Number
#1915
Type
pull request
State
closed
Author
lengau
Labels
Created
Updated
Closed

Current evaluation

Closed without merging. The CI security scanning changes are being redirected to the canonical/starflow repository. A separate pull request will implement the updated starflow version instead.

Suggested action:

No scores available.

Issue body

Adds two security scanning items: 1. A local dependencies security scan using trivy and osv 2. A (currently disabled) remote security scan using the Canonical security scanning API Snap build error is fixed in #1916 This is the applications version. Compare to the libraries version at https://github.com/canonical/craft-platforms/pull/52 Once approval is provided here, I will upstream to Starbase and reproduce on our other applications. NOTE: The Starbase version will be commented out below the libraries version, with a note that applications need to switch which version is commented.

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Closed without merging. The CI security scanning changes are being redirected to the canonical/starflow repository. A separate pull request will implement the updated starflow version instead.
qwen3.6-35b-a3b-mtp-q6 Closed and superseded. The author redirected the CI security scan additions to canonical/starflow and will open a separate pull request there using the starflow version.
qwen3.6-35b-a3b-mtp-q6 Closed without merging. Security scan configuration was redirected to the canonical/starflow repository. A separate pull request using the starflow version will be opened instead.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#573 ci: update usage of starflow security scanner starbase merged Merged after two approvals and passing CI. Updated the python-scans job in policy.yaml to use new starflow security scanner options, adding an osv-scanner.toml placeholder and path exclusions.
77%
#2027 build(ci): use starflow for policy and security scans charmcraft merged Merged update to the CI pipeline using starflow for policy and security scans. Approved by two reviewers, rebased on main, and reduced code by 12 lines across four files.
75%
#185 ci: fix security scanner debcraft merged Merged a one-line change to fix the CI security scanner. Approved by one reviewer and passing all CI checks, the pull request was successfully integrated.
75%
#5068 ci: add security scan snapcraft merged Merged following approval from two reviewers. The commit introduces a CI security scan, altering six files with 25 additions and 4 deletions to automate vulnerability checks.
74%
#859 ci: add security scanning job craft-parts merged Merged a pull request adding a CI security scanning job. The change modified one file with 15 additions, received approval from two reviewers, and successfully integrated automated security checks into the project workflow.
74%
#861 ci: use starflow policy checker craft-parts closed Closed without merging. The pull request to update CI to use the starflow policy checker was abandoned due to zero reviewer engagement, missing CI validation, and no subsequent activity.
73%
#200 ci: align policy OSV scan inputs with starbase craft-grammar merged Merged. Updated CI workflow to align OSV security scan inputs with starbase, added a root config file, and excluded docs from scans. All CI checks passed.
73%
#494 ci: add security scanning job craft-application merged Merged changes adding a CI security scanning job. Approved by two reviewers, the update introduces 15 lines to one file to automate pipeline security checks.
73%
#56 ci: add security scanning workflow craft-grammar merged Merged adds a CI workflow for security scanning. Approved by two reviewers, the change introduces a single configuration file to automate pipeline security checks.
72%
#716 ci: add security scan workflow rockcraft merged Merged to add a CI security scan workflow. Approved by two reviewers, the change modifies three files to automate security checks in the pipeline.
72%