ci: stop the advisory OSV scan from gating merges

osv-scanner.yml documents itself as detection-only (fail-on-vuln: false,
findings land in the Security tab) yet all-checks-pass listed it in needs,
so any failure result blocked the merge. In practice the failures are not
vulnerabilities: the "Upload to code-scanning" step hits GitHub's
per-installation API rate limit whenever several PRs run at once, and a
merge train of catalog entries went red on it across the board. The scan
still runs on every PR and weekly on main; it just reports instead of gating.
This commit is contained in:
teknium1
2026-09-14 19:15:00 -07:00
parent a982d2c882
commit 5db6d40874

View File

@@ -250,7 +250,11 @@ jobs:
- profile-artifact-check
- supply-chain
- review-labels
- osv-scanner
# osv-scanner is deliberately NOT a dependency: osv-scanner.yml is
# detection-only (fail-on-vuln: false, findings go to the Security tab)
# and its SARIF upload trips GitHub's per-installation API rate limit
# during merge trains, which turned an advisory scan into a merge
# blocker for whole batches of unrelated PRs.
# The image build runs in its own workflow (docker.yml) and reports
# its own check. It was never required here, because it is too slow
# to block a merge. A separate run also stops it from holding this