← Back to issue list

feat: new secscan action

View original Github issue

Metadata

Project
starflow
Number
#155
Type
pull request
State
open
Author
bepri
Labels
Created
Updated
Closed

Current evaluation

Adds a new secscan action for automated security scanning on tags or monthly workflows. Inactive for 73 days with 17 unresolved review comments and no reviewer engagement.

Suggested action: close stale

Reason: The PR has been inactive for 73 days with 17 unresolved review comments and zero reviewer engagement, indicating it is effectively abandoned. The author has not addressed the review feedback in over two months, and the unresolved comments suggest the PR needs changes that are no longer being pursued.

Impact: 60 Quick Win: 27.0 Staleness: 75 Complexity: 55 Confidence: 45

Issue body

Creates a new action to automate secscan. The intended use-case is for this to run on new tags, or as a monthly workflow against `latest/stable`. You can see it in action here: https://github.com/canonical/snapcraft/pull/6303 CRAFT-5208

Evaluation history

Date Model Scores Action Summary
qwen3.6-35b-a3b-mtp-q6
Impact: 60
Quick Win: 27.0
Staleness: 75
Complexity: 55
Confidence: 45
close stale Adds a new secscan action for automated security scanning on tags or monthly workflows. Inactive for 73 days with 17 unresolved review comments and no reviewer engagement.
qwen/qwen3.6-35b-a3b
Staleness: 45
Complexity: 45
Confidence: 90
needs review Introduces a new security scanning action for automated execution on new tags or monthly workflows. Currently pending review with 17 unresolved comments and all CI checks passing.
qwen3.6-35b-a3b-mtp-q6
Staleness: 15
Complexity: 25
Confidence: 85
needs review Introduces a new GitHub Action for automated security scanning, intended for tag pushes and monthly runs. Currently awaiting maintainer review with no comments or approvals.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#6303 ci: test new secscan action snapcraft open PR testing a new secscan CI action that is failing; inactive for 73 days with no maintainer engagement
75%
#6 feat: Security scanner starflow open Adds a security scanner GitHub workflow using the secscan API; author notes it doesn't work yet because runners lack access. Pending review, no CI, no comments, inactive for ~19 months.
74%