ci: align policy OSV scanner inputs with starbase
Metadata
Current evaluation
Superseded to align with branch naming requirements. The PR updated CI workflow and OSV scanner configuration to match starbase standards but was closed and reopened as a draft from the work/fix-osv branch.
Suggested action: —
No scores available.
Issue body
## Summary
- update .github/workflows/policy.yaml to pass OSV scanner inputs:
- osv-extra-args: "--config=osv-scanner.toml"
- osv-exclude-paths with docs
- uv-export-no-groups with docs and docs-sphinx-stack
- ensure requirements-find-args is not present in that with block
- set root osv-scanner.toml to:
- # OSV Scanner configuration
## Dependency/lockfile impact
No dependency or lockfile changes were required for this fix because it only adjusts reusable policy workflow inputs and scanner config file content.
## Validation
- verified workflow contains required keys and omits requirements-find-args
- verified osv-scanner.toml content matches expected single-line config comment
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Superseded to align with branch naming requirements. The PR updated CI workflow and OSV scanner configuration to match starbase standards but was closed and reopened as a draft from the work/fix-osv branch. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Superseded to align with branch naming requirements. Changes are being reopened as a draft from the work/fix-osv branch. The update adjusted CI policy OSV scanner inputs and config without modifying dependencies. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #199 ci: align policy OSV scan inputs with starbase | craft-grammar | closed | Superseded to align with required head branch work/fix-osv. The PR updated CI OSV scan inputs and added a placeholder config but was closed without merging. | |
| #253 ci: align policy OSV scanner inputs with starbase | craft-platforms | merged | Merged after passing all CI checks and approval. Updated the CI workflow to align OSV scanner inputs with starbase, configured osv-scanner.toml, and removed redundant arguments to standardize dependency scanning. | |
| #81 ci: align policy scan inputs with starbase PR 573 | craft-actions | closed | Superseded by PR #82, which applies the required head branch work/fix-osv. The original policy scan input alignments and OSV scanner configuration were replaced rather than merged. | |
| #1640 ci: align policy OSV scanner inputs | craft-parts | merged | Merged. Aligns CI OSV scanner workflow inputs with starbase PR #573 by adding osv-scanner.toml, configuring extra args and excluded paths, and removing legacy requirements-find-args. No dependency updates required. | |
| #200 ci: align policy OSV scan inputs with starbase | craft-grammar | merged | Merged. Updated CI workflow to align OSV security scan inputs with starbase, added a root config file, and excluded docs from scans. All CI checks passed. | |
| #235 ci: update OSV scanner to match starbase | craft-archives | merged | Merged changes to update the OSV scanner configuration, aligning it with the starbase repository. Approved by one reviewer, passed all CI checks, and modified four files to replicate upstream updates. | |
| #1639 ci: align policy OSV scanner inputs | craft-parts | closed | Superseded by pull request #1640. Adjusts OSV scanner workflow inputs, adds configuration files, and excludes specific paths to align security scanning policies. | |
| #82 ci: align policy scan inputs with starbase | craft-actions | closed | Closed without merging as unnecessary. The repository does not use the policy/scan-python workflow pattern targeted by the starbase #573 fix, rendering the alignment changes redundant. | |
| #1130 ci: fix OSV-scanner workflow path and exclude docs-only inputs | craft-application | merged | Merged. Corrected the OSV-scanner workflow config path to align with Starbase and excluded docs from scanning. Updated the uv lockfile for httplib2 and setuptools to resolve scanner failures. All CI checks passed. |