← Back to issue list

feat: Security scanner

View original Github issue

Metadata

Project
starflow
Number
#6
Type
pull request
State
open
Author
lengau
Labels
Created
Updated
Closed

Current evaluation

Adds a security scanner GitHub workflow using the secscan API; author notes it doesn't work yet because runners lack access. Pending review, no CI, no comments, inactive for ~19 months.

Suggested action: close stale

Reason: The PR is 705 days old with last activity 634 days ago, zero comments, and no CI runs. The author explicitly states it 'doesn't work yet because we don't have runners with access' — an external dependency that has never been resolved, and no evidence the secscan workflow was ever implemented elsewhere in the repo. The change is small (+106/-0, 2 files) and the feature (security scanning) remains relevant, but the PR has been blocked on infrastructure for ~2 years with no maintainer follow-up.

Impact: 30 Quick Win: 24.0 Staleness: 90 Complexity: 20 Confidence: 55

Issue body

Uses the secscan API. Doesn't work yet because we don't have runners with access.

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.8-27b
Impact: 30
Quick Win: 24.0
Staleness: 90
Complexity: 20
Confidence: 55
close stale Adds a security scanner GitHub workflow using the secscan API; author notes it doesn't work yet because runners lack access. Pending review, no CI, no comments, inactive for ~19 months.
qwen/qwen3.6-35b-a3b
Staleness: 90
Complexity: 40
Confidence: 75
close stale Adds a security scanner feature using the secscan API. Currently inactive for over a year, unreviewed, and non-functional due to missing runner access.
qwen3.6-35b-a3b-mtp-q6
Staleness: 95
Complexity: 20
Confidence: 90
close stale Adds a security scanner using the secscan API but remains non-functional due to missing runner access. Inactive for over 1.5 years with zero comments or maintainer engagement.
qwen3.6-35b-a3b-mtp-q6
Staleness: 95
Complexity: 40
Confidence: 85
close stale Implements a security scanner via the secscan API. Currently non-functional and inactive for 558 days due to missing runner access. Awaits infrastructure setup to enable testing and review.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#155 feat: new secscan action starflow open Adds a new secscan action for automated security scanning on tags or monthly workflows. Inactive for 73 days with 17 unresolved review comments and no reviewer engagement.
74%
#14 feat: golang security scanner starflow closed The Golang security scanner feature was closed without merging. It contained no code changes, received no reviews, and was abandoned.
71%
#128 ci: add security scan workflow craft-archives merged Merged a change adding a security scan workflow to the CI pipeline. Approved by two reviewers, the update adds 15 lines across one file to automate security checks.
71%
#1924 ci: add security scan workflow charmcraft merged Merged following approval by two reviewers. Introduces a CI security scan workflow, adding automated vulnerability checks across two files with 24 lines of configuration.
70%
#276 ci: add security scan workflow craft-cli merged Merged addition of a CI security scan workflow. Approved by two reviewers, the change introduces a new workflow file to automate security checks.
70%