-
Notifications
You must be signed in to change notification settings - Fork 0
security: eliminate warning-class output from central Security Scan #689
Copy link
Copy link
Open
Labels
area: apiAPI, protocol, event, or external contractAPI, protocol, event, or external contractarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenanceDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingSomething isn't workingpriority: highHigh-priority or P1 workHigh-priority or P1 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: securitySecurity vulnerability or security-specific remediationSecurity vulnerability or security-specific remediation
Description
Activity
Metadata
Metadata
Assignees
Labels
area: apiAPI, protocol, event, or external contractAPI, protocol, event, or external contractarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenanceDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingSomething isn't workingpriority: highHigh-priority or P1 workHigh-priority or P1 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: securitySecurity vulnerability or security-specific remediationSecurity vulnerability or security-specific remediation
Type
Projects
- StatusShow more project fieldsIn Progress
Evidence
Current-head Naruon PR #1206 run
30637062852completed with zero Medium-or-higher findings, but the centralSecurity Scanlog still contains strict-contract warning/fatal-class output:[pip] Unable to find python site-packages directory. License detection is skipped.--outputis deprecated in favor of--output-filefor base/head scans.--outputis deprecated in favor of--output-files.fatal: bad object <synthetic merge sha>before falling back to server-side calculation.The actual scan evidence was clean: Trivy 0 CRITICAL/HIGH/MEDIUM, dependency-review 0 moderate+, OSV reporter SARIF 0, open code-scanning alerts 0. This issue tracks log-contract remediation rather than a package/CVE finding.
Acceptance
fataloutput.