Make Trustabl scan advisory as intended - #60
Merged
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Contributor
Trustabl scan
Readiness goes from Readiness now 🟩🟩🟩🟩🟩🟩🟩🟩🟩🟩 Projected if all findings resolved 🟩🟩🟩🟩🟩🟩🟩🟩🟩🟩 Findings by severity
Projected headroom — estimate, not a re-scan
Projected by re-applying trustabl's own scoring with the listed findings resolved (nothing new introduced). Treat as guidance, not a guarantee.
❌ Failed
Failed due to: trustabl gated (medium+ or --strict) |
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
PR #59 added Trustabl as an advisory scanner, but the workflow still let Trustabl's native medium+ exit code fail the scan job. The original job-level
continue-on-erroronly tolerated the failed job at the workflow level; it did not make the scan job/step itself green.This PR aligns the implementation with that stated intent:
trustabl/trustabl-actionfrom v0.4.1 to v0.4.3, pinned to commitd97575c864814bf4965fa2c72c044224d372723a;severity-threshold: noneexplicitly;continue-on-error: trueto the Trustabl step instead of the entire job, so scanner findings are advisory without masking checkout/setup failures.Root cause observed
The scan reports seven
CREW-006medium findings for mutating CrewAI tools without idempotency keys. Those findings pre-date PR #59 and are real reliability issues, but they are not caused by the scanner workflow itself.The old v0.1.6 scan also skipped 13 newer rules because the engine could not understand them. v0.1.9 removes that incomplete-scan notice.
Validation
PR run
34700359806completed thescanjob successfully. The seven medium findings are still reported, SARIF/artifacts are still uploaded, and the scanner remains advisory as intended.