ci: add security scanner job
Metadata
Current evaluation
Merged. Added a CI security scanner job that fails on detected vulnerabilities. Reviewers approved the change, noting that warning-level issues currently return exit code 0.
Suggested action: —
No scores available.
Issue body
- [ ] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)?
-----
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged. Added a CI security scanner job that fails on detected vulnerabilities. Reviewers approved the change, noting that warning-level issues currently return exit code 0. |
Update history
| Date | Change |
|---|---|
| created |
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #494 ci: add security scanning job | craft-application | merged | Merged changes adding a CI security scanning job. Approved by two reviewers, the update introduces 15 lines to one file to automate pipeline security checks. | |
| #859 ci: add security scanning job | craft-parts | merged | Merged a pull request adding a CI security scanning job. The change modified one file with 15 additions, received approval from two reviewers, and successfully integrated automated security checks into the project workflow. | |
| #5068 ci: add security scan | snapcraft | merged | Merged following approval from two reviewers. The commit introduces a CI security scan, altering six files with 25 additions and 4 deletions to automate vulnerability checks. | |
| #185 ci: fix security scanner | debcraft | merged | Merged a one-line change to fix the CI security scanner. Approved by one reviewer and passing all CI checks, the pull request was successfully integrated. | |
| #1924 ci: add security scan workflow | charmcraft | merged | Merged following approval by two reviewers. Introduces a CI security scan workflow, adding automated vulnerability checks across two files with 24 lines of configuration. | |
| #128 ci: add security scan workflow | craft-archives | merged | Merged a change adding a security scan workflow to the CI pipeline. Approved by two reviewers, the update adds 15 lines across one file to automate security checks. | |
| #218 ci: add security scan workflow | craft-store | merged | Merged to add a CI security scan workflow. Approved by two reviewers, the change introduces thirteen lines across one file to automate pipeline security checks. | |
| #716 ci: add security scan workflow | rockcraft | merged | Merged to add a CI security scan workflow. Approved by two reviewers, the change modifies three files to automate security checks in the pipeline. | |
| #56 ci: add security scanning workflow | craft-grammar | merged | Merged adds a CI workflow for security scanning. Approved by two reviewers, the change introduces a single configuration file to automate pipeline security checks. | |
| #426 ci: fix security scanner | imagecraft | merged | Merged a one-line fix for the zizmor security scanner in the CI pipeline. Approved by one reviewer and passed required checks before integration. |