Merge pull request #111469 from NousResearch/ci/osv-scan-non-blocking
CI: the advisory OSV scan no longer gates merges
This commit is contained in:
6
.github/workflows/ci.yaml
vendored
6
.github/workflows/ci.yaml
vendored
@@ -250,7 +250,11 @@ jobs:
|
||||
- profile-artifact-check
|
||||
- supply-chain
|
||||
- review-labels
|
||||
- osv-scanner
|
||||
# osv-scanner is deliberately NOT a dependency: osv-scanner.yml is
|
||||
# detection-only (fail-on-vuln: false, findings go to the Security tab)
|
||||
# and its SARIF upload trips GitHub's per-installation API rate limit
|
||||
# during merge trains, which turned an advisory scan into a merge
|
||||
# blocker for whole batches of unrelated PRs.
|
||||
# The image build runs in its own workflow (docker.yml) and reports
|
||||
# its own check. It was never required here, because it is too slow
|
||||
# to block a merge. A separate run also stops it from holding this
|
||||
|
||||
Reference in New Issue
Block a user