ci: stop the advisory OSV scan from gating merges
osv-scanner.yml documents itself as detection-only (fail-on-vuln: false, findings land in the Security tab) yet all-checks-pass listed it in needs, so any failure result blocked the merge. In practice the failures are not vulnerabilities: the "Upload to code-scanning" step hits GitHub's per-installation API rate limit whenever several PRs run at once, and a merge train of catalog entries went red on it across the board. The scan still runs on every PR and weekly on main; it just reports instead of gating.
This commit is contained in:
6
.github/workflows/ci.yaml
vendored
6
.github/workflows/ci.yaml
vendored
@@ -250,7 +250,11 @@ jobs:
|
||||
- profile-artifact-check
|
||||
- supply-chain
|
||||
- review-labels
|
||||
- osv-scanner
|
||||
# osv-scanner is deliberately NOT a dependency: osv-scanner.yml is
|
||||
# detection-only (fail-on-vuln: false, findings go to the Security tab)
|
||||
# and its SARIF upload trips GitHub's per-installation API rate limit
|
||||
# during merge trains, which turned an advisory scan into a merge
|
||||
# blocker for whole batches of unrelated PRs.
|
||||
# The image build runs in its own workflow (docker.yml) and reports
|
||||
# its own check. It was never required here, because it is too slow
|
||||
# to block a merge. A separate run also stops it from holding this
|
||||
|
||||
Reference in New Issue
Block a user