brave / brave/security-action

Evaluate the use of Sarif instead of Reviewdog

Open
#65 4 comments 0 reactions 1 assignee Assigned to @thypon View on GitHub
enhancement
Dominant language
JavaScript
Stars
22
Forks
8
Avg merge
2d 6h
Merged PRs (30d)
40

Description

## Pro

- It's supported by GitHub natively
- Fancy new thingy

## Cons

- We need to port the checks we have
- We need to rewrite the missing checks (xmllint one, maybe)
- We need to rewrite and get the other scripts working:

* tfsec with multi-dir support, and proper diffing
* xmllint that does not support any output if not text
* blocklist for semgrep findings and custom rulesets

## Open Qs

- Rather limited console support, so slow iteration (maybe?)
- How do we test that the serif output is fine? Is there any validator?

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.