google / google/osv-scanner

Github Reusable Workflow - being able to fail to job by a minimum severity

Open
#712 4 comments 0 reactions 0 assignees View on GitHub
backlog enhancement
Dominant language
Go
Stars
11k
Forks
792
Avg merge
1d 20h
Merged PRs (30d)
48

Description

Hi, is there a way to set a minimum CVSS for failing the reusable PR scanner workflow?
For example, new package with CVE of 2.1 CVSS, only print log, but won't fail the step.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.