Skip to content

Conversation

@spencerschrock
Copy link
Member

What kind of change does this PR introduce?

config tweak

What is the current behavior?

All transitive dependency scanning was disabled

What is the new behavior (if this is a feature change)?**

Only the Python transitive scanning is disabled.

Plugins are a new osv-scanner/osv-scalibr way of disabling specific features, which give us finer control over what features to toggle.

  • Tests for the changes have been added (for bug fixes/features)

Which issue(s) this PR fixes

NONE

Special notes for your reviewer

Does this PR introduce a user-facing change?

For user-facing changes, please add a concise, human-readable release note to
the release-note

(In particular, describe what changes users might need to make in their
application as a result of this pull request.)

Re-enabled transitive scanning in osv-scanner v2 except for PyPI

@codecov
Copy link

codecov bot commented Nov 11, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 69.60%. Comparing base (353ed60) to head (23ef0a5).
⚠️ Report is 280 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #4848      +/-   ##
==========================================
+ Coverage   66.80%   69.60%   +2.80%     
==========================================
  Files         230      251      +21     
  Lines       16602    15654     -948     
==========================================
- Hits        11091    10896     -195     
+ Misses       4808     3888     -920     
- Partials      703      870     +167     
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Plugins are a new osv-scanner/osv-scalibr way of disabling specific
features, which give us finer control over what features to toggle.

Signed-off-by: Spencer Schrock <sschrock@google.com>
@spencerschrock spencerschrock marked this pull request as ready for review November 12, 2025 16:30
@spencerschrock spencerschrock requested a review from a team as a code owner November 12, 2025 16:30
@spencerschrock spencerschrock requested review from AdamKorcz and jeffmendoza and removed request for a team November 12, 2025 16:30
@dosubot dosubot bot added the size:XS This PR changes 0-9 lines, ignoring generated files. label Nov 12, 2025
@spencerschrock
Copy link
Member Author

/scdiff generate Vulnerabilities

@github-actions
Copy link

@spencerschrock spencerschrock merged commit 80ee3ec into ossf:main Nov 13, 2025
37 checks passed
@spencerschrock spencerschrock deleted the osv-transitive branch November 13, 2025 19:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants