eclipse-tractusx / managed-identity-wallet

Apache License 2.0
9 stars 22 forks source link

ci: don't report medium and high openly #200

Closed borisrizov-zf closed 7 months ago

borisrizov-zf commented 9 months ago

Summary

Security scans shouldn't post reports which contain High and Medium findings for the open public as it would present a security issue.

Solution

Edit the reports to show only non-critical errors and create reports in the security tab.

borisrizov-zf commented 7 months ago

The acceptable solution to this is to update the DAST scan file and remove line 123-127 and add the retention-days: 1 option to the report. This has been approved by sec as a solution.

borisrizov-zf commented 7 months ago

Closed by #256