feat: add security-insights.yml for OSPS baseline scanning#50
feat: add security-insights.yml for OSPS baseline scanning#50jpower432 merged 6 commits intogemaraproj:mainfrom
Conversation
e36c65a to
4b584ed
Compare
jpower432
left a comment
There was a problem hiding this comment.
Thanks @sonupreetam. Added one suggestion for an additional tool in the list.
Kusari Analysis Results:
No pinned version dependency changes, code issues or exposed secrets detected! Note View full detailed analysis result for more information on the output and the checks that were run.
Found this helpful? Give it a 👍 or 👎 reaction! |
5ebb02e to
b53ca96
Compare
|
Kusari PR Analysis rerun based on - b53ca96 performed at: 2026-04-08T09:56:03Z - link to updated analysis |
|
@kusari-inspector rerun |
|
🔄 Run triggered at 11:17:56 UTC. Starting fresh analysis... |
|
Kusari PR Analysis rerun based on - b53ca96 performed at: 2026-04-08T11:18:19Z - link to updated analysis |
8530396 to
aea49b5
Compare
|
@eddie-knight & @jpower432 the DCO check failed specifically on the suggestions applied via the GitHub UI (commits 05d3cbf and 8530396 were missing Signed-off-by). So I rebased the branch and force pushed cleanly. |
jpower432
left a comment
There was a problem hiding this comment.
@sonupreetam This looks good, but I see some extra files in the diff. This might need a rebase before merge.
Signed-off-by: sonupreetam <spreetam@redhat.com>
Signed-off-by: sonupreetam <spreetam@redhat.com>
Signed-off-by: sonupreetam <spreetam@redhat.com>
Signed-off-by: sonupreetam <spreetam@redhat.com>
aea49b5 to
1c74728
Compare
Co-authored-by: Eddie Knight <knight@linux.com> Signed-off-by: sonupreetam <spreetam@redhat.com>
Co-authored-by: Eddie Knight <knight@linux.com> Signed-off-by: sonupreetam <spreetam@redhat.com>
|
@jpower432 Yes Thank you for catching this. Updated with the suggestions. |
Summary
security-insights.ymlto the project root to enable OSPS Baseline scanninggemaraproj/gemarabaseline-scanner.ymlworkflow was already present in the repositoryCloses #16
Changes
security-insights.yml: new file declaring schema version, repository metadata, core team, license, and security tooling (Dependabot SCA + CodeQL SAST) following the Security Insights v2 specTest plan
security-insights.ymlis valid against the Security Insights v2 schema