ci: ignore unfixable OSVs
Metadata
Current evaluation
Merged a pull request adding a single configuration line to CI to ignore unfixable OSV scanner findings. The change passed all CI checks, received one approval, and was successfully integrated into the main branch.
Suggested action: —
No scores available.
Issue body
- [ ] Have you followed the guidelines for contributing?
- [ ] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)?
- [ ] Have you successfully run `make lint && make test`?
---
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged a pull request adding a single configuration line to CI to ignore unfixable OSV scanner findings. The change passed all CI checks, received one approval, and was successfully integrated into the main branch. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged a maintainer change updating the CI pipeline to automatically ignore unfixable OSV alerts, streamlining security scanning by filtering known unresolvable vulnerabilities. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #2773 ci: ignore unfixable OSVs | charmcraft | merged | Merged CI configuration to ignore unfixable OSV warnings, replacing #2765 with the starbase #573 pattern. Approved by two reviewers and merged despite failing snap-store-tests and spread-select checks. | |
| #5487 ci: remove config for osv scanner | snapcraft | merged | Merged after approval by two reviewers. Removed expired OSV scanner configuration from CI. Updated one file with a four-line reduction. All required CI checks passed prior to merge. | |
| #1299 ci: fix osv scanner on docs | rockcraft | merged | Merged a configuration update to make the OSV scanner ignore documentation files. Approved by a reviewer, passed CI checks, and resolved scanner false positives in the docs directory with a single file change. | |
| #5822 ci: ignore unresolvable OSV | snapcraft | merged | Merged a PR to ignore an unresolvable OSV scan failure in CI. The vulnerability cannot be resolved until pip 25.3 releases on October 30th. Approved by two reviewers and passed all CI checks. | |
| #505 ci(osv-scanner): ignore integration tests | starbase | merged | Merged CI configuration changes to configure osv-scanner to ignore integration tests, preventing false positive dependency warnings. Approved by two reviewers with all checks passing. | |
| #6347 ci(scan): fix osv scanner on docs | snapcraft | merged | Merged after approval. The change updates the CI pipeline to fix the OSV security scanner for documentation builds, resolving the scanning configuration issue. | |
| #157 ci(scan): allow ignoring files/directories | starflow | merged | Merged after approval and passing CI. Enables the OSV scanner to ignore specified files and directories, deferring documentation dependency fixes to the Sphinx Stack and Starbase update pipeline. | |
| #199 ci: align policy OSV scan inputs with starbase | craft-grammar | closed | Superseded to align with required head branch work/fix-osv. The PR updated CI OSV scan inputs and added a placeholder config but was closed without merging. | |
| #185 ci: fix security scanner | debcraft | merged | Merged a one-line change to fix the CI security scanner. Approved by one reviewer and passing all CI checks, the pull request was successfully integrated. | |
| #1640 ci: align policy OSV scanner inputs | craft-parts | merged | Merged. Aligns CI OSV scanner workflow inputs with starbase PR #573 by adding osv-scanner.toml, configuring extra args and excluded paths, and removing legacy requirements-find-args. No dependency updates required. |