canonical / canonical/starflow

Use osv-scanner to scan `uv.lock` files

Open
#28 1 comment 0 reactions 0 assignees View on GitHub
Status: Triaged Type: Enhancement
Dominant language
Python
Stars
3
Forks
8
Avg merge
2h 36m
Merged PRs (30d)
11

Description

The `scan-python` workflow should scan `uv.lock` with osv-scanner.

Blocked by https://github.com/google/osv-scanner/issues/1406

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the repository's `scan-python` workflow and inspect how its current dependency files are passed to osv-scanner. Check the linked osv-scanner issue #1406 before making changes, since this work is explicitly blocked. Done means the workflow scans `uv.lock` files successfully without breaking its existing scans.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, python
Domain
ci-cd, security
Issue type
Feature
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.