Repository navigation
ci: keep the Dockle threshold at WARN in the server template - #265
Conversation
Dockle does not accept the old value "high" and falls back to WARN, so WARN keeps the behavior of the server repositories. FATAL would relax the scan. Co-authored-by: Claude <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe Dockle Linter failure threshold in the repository server CVE scan workflow changes from FATAL to WARN. The exit code remains 42. ChangesDockle workflow threshold
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~5 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to WARN-level findings will now fail the scan with exit code 42, rather than only FATAL findings. This is a stricter gate, and no concrete merge-blocking risk is established. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The Dockle step in the
serverCVE scan template now usesfailure-threshold: WARN, the level that the server repositories run today.Why
#263 changed the value from
hightoFATAL. Dockle does not accepthigh. It falls back toWARN, so the scan has always failed onWARNfindings. Onory/kratosandory/hydra, the Dockle step passes with that value.FATALwould relax the scan, which is a policy change and not a fix.WARNkeeps the current behavior with a valid value.Evidence
actionlint,scripts/check-workflows.shandmake testpass.Risk
None for synced repositories.
scripts/sync.shexcludes all four server repositories, so this template reaches no repository.Co-authored-by: Claude noreply@anthropic.com
Summary by CodeRabbit