galasa-dev / projectmanagement

Project Management repo for Issues and ZenHub
7 stars 4 forks source link

Louisa to get permission to change status of Code Secrets in Galasa Repos #1756

Open louisa-seers opened 7 months ago

louisa-seers commented 7 months ago

I have opened a support ticket with the Linux Foundation to gain permission to change the status of code secrets within Galasa with @techcobweb.

louisa-seers commented 4 months ago

Heather Willson commented on Monday 6th May:

Hi Louisa, I apologize for the lateness of the response here, but I'm having our LFX Security team review your scans and provide answers.

techcobweb commented 4 months ago

Seems to be able to change the status, but can't make the numbers smaller.

louisa-seers commented 3 months ago

Hi Heather,

We have merged branches and removed code since the scan was taken and there have been no changes in the dashboard.

How do we kick a scan off to rescan?

Louisa

—-—-—-— Reply above this line. Heather commented:

Hello Louisa Seers i've confirmed that there's no way to dismiss the licenses, only that they will be removed from the dashboard when the future branches are merged into the main branch.

The only 0 I see now for Code secrets is the 0.0 risk score that is the best score possible from Blubracket https://docs.blubracket.com/release-notes/2021-02-02/#repo-risk-score-and-secret-risk-score

If there's something I've missed, please let me know.

View request · Turn off this request's notifications

This is shared with Louisa Seers.

Help Center, powered by Jira Service Management, sent you this message.

louisa-seers commented 3 months ago

Heather Willson commented:

Hello Louisa, scans are updated weekly as long as changes to the repo are detected. I've asked for an investigation and a new scan to be kicked off for Galasa and will let you know when completed.