← Back to issue list

ci: ignore unfixable OSVs

View original Github issue

Metadata

Project
craft-platforms
Number
#247
Type
pull request
State
merged
Author
bepri
Labels
Created
Updated
Closed

Current evaluation

Merged a pull request adding a single configuration line to CI to ignore unfixable OSV scanner findings. The change passed all CI checks, received one approval, and was successfully integrated into the main branch.

Suggested action:

No scores available.

Issue body

- [ ] Have you followed the guidelines for contributing? - [ ] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)? - [ ] Have you successfully run `make lint && make test`? ---

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged a pull request adding a single configuration line to CI to ignore unfixable OSV scanner findings. The change passed all CI checks, received one approval, and was successfully integrated into the main branch.
qwen3.6-35b-a3b-mtp-q6 Merged a maintainer change updating the CI pipeline to automatically ignore unfixable OSV alerts, streamlining security scanning by filtering known unresolvable vulnerabilities.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#2773 ci: ignore unfixable OSVs charmcraft merged Merged CI configuration to ignore unfixable OSV warnings, replacing #2765 with the starbase #573 pattern. Approved by two reviewers and merged despite failing snap-store-tests and spread-select checks.
82%
#5487 ci: remove config for osv scanner snapcraft merged Merged after approval by two reviewers. Removed expired OSV scanner configuration from CI. Updated one file with a four-line reduction. All required CI checks passed prior to merge.
81%
#1299 ci: fix osv scanner on docs rockcraft merged Merged a configuration update to make the OSV scanner ignore documentation files. Approved by a reviewer, passed CI checks, and resolved scanner false positives in the docs directory with a single file change.
79%
#5822 ci: ignore unresolvable OSV snapcraft merged Merged a PR to ignore an unresolvable OSV scan failure in CI. The vulnerability cannot be resolved until pip 25.3 releases on October 30th. Approved by two reviewers and passed all CI checks.
78%
#505 ci(osv-scanner): ignore integration tests starbase merged Merged CI configuration changes to configure osv-scanner to ignore integration tests, preventing false positive dependency warnings. Approved by two reviewers with all checks passing.
76%
#6347 ci(scan): fix osv scanner on docs snapcraft merged Merged after approval. The change updates the CI pipeline to fix the OSV security scanner for documentation builds, resolving the scanning configuration issue.
74%
#157 ci(scan): allow ignoring files/directories starflow merged Merged after approval and passing CI. Enables the OSV scanner to ignore specified files and directories, deferring documentation dependency fixes to the Sphinx Stack and Starbase update pipeline.
74%
#199 ci: align policy OSV scan inputs with starbase craft-grammar closed Superseded to align with required head branch work/fix-osv. The PR updated CI OSV scan inputs and added a placeholder config but was closed without merging.
74%
#185 ci: fix security scanner debcraft merged Merged a one-line change to fix the CI security scanner. Approved by one reviewer and passing all CI checks, the pull request was successfully integrated.
74%
#1640 ci: align policy OSV scanner inputs craft-parts merged Merged. Aligns CI OSV scanner workflow inputs with starbase PR #573 by adding osv-scanner.toml, configuring extra args and excluded paths, and removing legacy requirements-find-args. No dependency updates required.
73%