← Back to issue list

fix(scan): fix path resolution for osv-scanner file arguments

View original Github issue

Metadata

Project
starflow
Number
#160
Type
pull request
State
merged
Author
bepri
Labels
Created
Updated
Closed

Current evaluation

Merged fix for osv-scanner path resolution. Removes the required source/ prefix in osv-extra-args, enabling direct config file references. Approved by one reviewer and passed CI checks prior to merge.

Suggested action:

No scores available.

Issue body

Fixes an issue where something like `osv-extra-args: "--config-file=osv-scanner.toml"` would fail. The original implementation of this action would leak an implementation detail that we copied the project into a directory named `source/`, and so any file names in `osv-extra-args` had to be prefixed, like `source/osv-scanner.toml`. I fixed one instance of this leaking in #157, but I missed this one.

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged fix for osv-scanner path resolution. Removes the required source/ prefix in osv-extra-args, enabling direct config file references. Approved by one reviewer and passed CI checks prior to merge.
qwen3.6-35b-a3b-mtp-q6 Merged fix for osv-scanner path resolution. Removes the hardcoded source/ prefix requirement from osv-extra-args, enabling direct config file references without manual path adjustments.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#6347 ci(scan): fix osv scanner on docs snapcraft merged Merged after approval. The change updates the CI pipeline to fix the OSV security scanner for documentation builds, resolving the scanning configuration issue.
77%
#1299 ci: fix osv scanner on docs rockcraft merged Merged a configuration update to make the OSV scanner ignore documentation files. Approved by a reviewer, passed CI checks, and resolved scanner false positives in the docs directory with a single file change.
76%
#5487 ci: remove config for osv scanner snapcraft merged Merged after approval by two reviewers. Removed expired OSV scanner configuration from CI. Updated one file with a four-line reduction. All required CI checks passed prior to merge.
76%
#988 ci: fix OSV scanner policy workflow craft-providers merged Merged fix for OSV scanner policy workflow failures. Updated scan-python inputs, passed configuration via osv-extra-args, excluded docs from UV export, and added osv-scanner.toml. All CI checks passed.
75%
#1130 ci: fix OSV-scanner workflow path and exclude docs-only inputs craft-application merged Merged. Corrected the OSV-scanner workflow config path to align with Starbase and excluded docs from scanning. Updated the uv lockfile for httplib2 and setuptools to resolve scanner failures. All CI checks passed.
74%
#1640 ci: align policy OSV scanner inputs craft-parts merged Merged. Aligns CI OSV scanner workflow inputs with starbase PR #573 by adding osv-scanner.toml, configuring extra args and excluded paths, and removing legacy requirements-find-args. No dependency updates required.
73%
#505 ci(osv-scanner): ignore integration tests starbase merged Merged CI configuration changes to configure osv-scanner to ignore integration tests, preventing false positive dependency warnings. Approved by two reviewers with all checks passing.
72%