Open graemechristie opened 10 months ago
The current rules in the exported Sarif file do not include the security-severity property. A per the docs below, this is recommended for security rules.
https://docs.github.com/en/code-security/code-scanning/integrating-with-code-scanning/sarif-support-for-code-scanning#reportingdescriptor-object
Likewise, the precision property is also recommended and used in concert with the security severity to assess the impact of the recorded CVE's.
This issue has not had any activity for 60 days and will be automatically closed in two weeks
Automatically closing stale issue
The current rules in the exported Sarif file do not include the security-severity property. A per the docs below, this is recommended for security rules.
https://docs.github.com/en/code-security/code-scanning/integrating-with-code-scanning/sarif-support-for-code-scanning#reportingdescriptor-object
Likewise, the precision property is also recommended and used in concert with the security severity to assess the impact of the recorded CVE's.