Skip to content

enforce fossa blocking on critical high vulnerabilities#141

Open
johnvincentcorpuz wants to merge 1 commit into
mainfrom
fossa_guard_vuln
Open

enforce fossa blocking on critical high vulnerabilities#141
johnvincentcorpuz wants to merge 1 commit into
mainfrom
fossa_guard_vuln

Conversation

@johnvincentcorpuz

Copy link
Copy Markdown
Collaborator

This pull request makes a configuration update to the .github/workflow-config.json file to strengthen security measures. The most important change is that vulnerabilities marked as "critical" or "high" will now block workflows instead of just being reported.

Security and workflow enforcement:

  • Changed the vulnerability check mode from "REPORT" to "BLOCK", so workflows will be blocked if critical or high vulnerabilities are detected.
    🧩 Complexity Level: 🟢 Low

⏱️ Estimated Review Time: 10–15 minutes

Signed-off-by: John Corpuz <john.corpuz@solace.com>
@github-actions

Copy link
Copy Markdown

✅ FOSSA Guard: Licensing (SolaceLabs_solace-ai-connector) • PASSED

Compared against main (e1cefe649bba2adf41ff6e980affc7950b0358bd) • 0 new, 11 total (11 in base)

Scan Report | View Details in FOSSA

@github-actions

Copy link
Copy Markdown

⚠️ FOSSA Guard: Vulnerability (SolaceLabs_solace-ai-connector) • 1 issue

Compared against main (e1cefe649bba2adf41ff6e980affc7950b0358bd) • 1 new, 3 total (2 in base)

ℹ️ Privacy mode enabled - detailed violation information hidden.

  • Low: 1 issue(s)

Scan Report | View Details in FOSSA

@sonarqube-solacecloud

Copy link
Copy Markdown

Quality Gate passed Quality Gate passed

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarQube

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant