← Back to issue list

ci: ignore sample files in OSV scans

View original Github issue

Metadata

Project
rockcraft
Number
#962
Type
pull request
State
merged
Author
lengau
Labels
Created
Updated
Closed

Current evaluation

Merged CI configuration changes to ignore documentation and spread test sample files in OSV scans. Approved by two reviewers with all checks passing, preventing security alerts for demo-only content.

Suggested action:

No scores available.

Issue body

This ignores files from documentation and spread tests in our OSV scans. They're probably okay to have vulnerable versions since they're for demo purposes only. - [x] Have you followed the guidelines for contributing? - [x] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)? - [x] Have you successfully run `make lint && make test`? ---

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged CI configuration changes to ignore documentation and spread test sample files in OSV scans. Approved by two reviewers with all checks passing, preventing security alerts for demo-only content.
qwen3.6-35b-a3b-mtp-q6 Merged CI updates to exclude documentation and spread test sample files from OSV vulnerability scans. These demo files are expected to contain outdated dependencies, so excluding them prevents false positives and streamlines security scanning.
qwen3.6-35b-a3b-mtp-q6 Merged a CI configuration update that excludes documentation and spread test sample files from OSV security scans. Excluding these demonstration files prevents false positive vulnerability alerts. The change passed all linting and testing checks.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#1299 ci: fix osv scanner on docs rockcraft merged Merged a configuration update to make the OSV scanner ignore documentation files. Approved by a reviewer, passed CI checks, and resolved scanner false positives in the docs directory with a single file change.
81%
#5487 ci: remove config for osv scanner snapcraft merged Merged after approval by two reviewers. Removed expired OSV scanner configuration from CI. Updated one file with a four-line reduction. All required CI checks passed prior to merge.
79%
#157 ci(scan): allow ignoring files/directories starflow merged Merged after approval and passing CI. Enables the OSV scanner to ignore specified files and directories, deferring documentation dependency fixes to the Sphinx Stack and Starbase update pipeline.
79%
#246 ci: ignore docs for CSVs craft-platforms merged Merged a CI configuration update to ignore documentation files during CSV processing. Approved by one reviewer and merged after passing most checks, despite one failing OSV-scanner job.
76%
#6347 ci(scan): fix osv scanner on docs snapcraft merged Merged after approval. The change updates the CI pipeline to fix the OSV security scanner for documentation builds, resolving the scanning configuration issue.
76%
#505 ci(osv-scanner): ignore integration tests starbase merged Merged CI configuration changes to configure osv-scanner to ignore integration tests, preventing false positive dependency warnings. Approved by two reviewers with all checks passing.
76%
#200 ci: align policy OSV scan inputs with starbase craft-grammar merged Merged. Updated CI workflow to align OSV security scan inputs with starbase, added a root config file, and excluded docs from scans. All CI checks passed.
73%
#247 ci: ignore unfixable OSVs craft-platforms merged Merged a pull request adding a single configuration line to CI to ignore unfixable OSV scanner findings. The change passed all CI checks, received one approval, and was successfully integrated into the main branch.
72%
#5068 ci: add security scan snapcraft merged Merged following approval from two reviewers. The commit introduces a CI security scan, altering six files with 25 additions and 4 deletions to automate vulnerability checks.
72%
#1498 ci(osv-scanner): ignore integration tests craft-parts merged Merged to configure OSV-scanner to ignore integration tests, preventing false positive dependency alerts. Approved by two reviewers and upstreamed to canonical/starbase.
71%