Skip to content

Enable static code analysis #56

@gonzolively

Description

@gonzolively

Security Issue Description

We need to enable static code analysis for the ocre-runtime in our current CI/CD pipeline for various reasons. The first being security. The second being to ensure we're up to date with OpenSSF best practices and can advance our badge status to "passing", as it is currently "in progress".

Affected Components

N/A

Severity & Impact

  • Low - Minor security concern, limited impact
  • Medium - Potential risk, but not critical
  • High - Significant risk, requires immediate attention
  • Critical - Severe vulnerability, urgent resolution needed

Steps to Reproduce (if applicable)

N/A

Suggested Remediation

This is up for discussion as we need to evaluate which tools/toolchains would be best for the ocre-runtime and its components.

Additional Context

Metadata

Metadata

Assignees

No one assigned

    Labels

    securityTask related to security issues in Ocre

    Type

    Projects

    Status

    Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions