ci: fix osv scanner on docs
Metadata
Current evaluation
Merged a configuration update to make the OSV scanner ignore documentation files. Approved by a reviewer, passed CI checks, and resolved scanner false positives in the docs directory with a single file change.
Suggested action: —
No scores available.
Issue body
This should make OSV scanner ignore anything that comes from the docs now.
---
- [ ] I've followed the [contribution guidelines](https://github.com/canonical/rockcraft/blob/main/CONTRIBUTING.md).
- [ ] I've signed the [CLA](http://www.ubuntu.com/legal/contributors/).
- [ ] I've successfully run `make lint && make test`.
- [ ] I've added or updated any relevant documentation.
- [ ] In documents I changed, I [added a meta description](https://canonical-starflow.readthedocs-hosted.com/how-to/add-a-page-meta-description/) if one was missing.
- [ ] I've updated the relevant release notes.
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged a configuration update to make the OSV scanner ignore documentation files. Approved by a reviewer, passed CI checks, and resolved scanner false positives in the docs directory with a single file change. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged CI configuration changes that exclude documentation files from OSV scanning, resolving false positive security alerts in the docs directory. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #6347 ci(scan): fix osv scanner on docs | snapcraft | merged | Merged after approval. The change updates the CI pipeline to fix the OSV security scanner for documentation builds, resolving the scanning configuration issue. | |
| #5487 ci: remove config for osv scanner | snapcraft | merged | Merged after approval by two reviewers. Removed expired OSV scanner configuration from CI. Updated one file with a four-line reduction. All required CI checks passed prior to merge. | |
| #1130 ci: fix OSV-scanner workflow path and exclude docs-only inputs | craft-application | merged | Merged. Corrected the OSV-scanner workflow config path to align with Starbase and excluded docs from scanning. Updated the uv lockfile for httplib2 and setuptools to resolve scanner failures. All CI checks passed. | |
| #988 ci: fix OSV scanner policy workflow | craft-providers | merged | Merged fix for OSV scanner policy workflow failures. Updated scan-python inputs, passed configuration via osv-extra-args, excluded docs from UV export, and added osv-scanner.toml. All CI checks passed. | |
| #962 ci: ignore sample files in OSV scans | rockcraft | merged | Merged CI configuration changes to ignore documentation and spread test sample files in OSV scans. Approved by two reviewers with all checks passing, preventing security alerts for demo-only content. | |
| #246 ci: ignore docs for CSVs | craft-platforms | merged | Merged a CI configuration update to ignore documentation files during CSV processing. Approved by one reviewer and merged after passing most checks, despite one failing OSV-scanner job. | |
| #505 ci(osv-scanner): ignore integration tests | starbase | merged | Merged CI configuration changes to configure osv-scanner to ignore integration tests, preventing false positive dependency warnings. Approved by two reviewers with all checks passing. | |
| #247 ci: ignore unfixable OSVs | craft-platforms | merged | Merged a pull request adding a single configuration line to CI to ignore unfixable OSV scanner findings. The change passed all CI checks, received one approval, and was successfully integrated into the main branch. | |
| #235 ci: update OSV scanner to match starbase | craft-archives | merged | Merged changes to update the OSV scanner configuration, aligning it with the starbase repository. Approved by one reviewer, passed all CI checks, and modified four files to replicate upstream updates. | |
| #157 ci(scan): allow ignoring files/directories | starflow | merged | Merged after approval and passing CI. Enables the OSV scanner to ignore specified files and directories, deferring documentation dependency fixes to the Sphinx Stack and Starbase update pipeline. |