🤖 Exit on CRITICAL vulnerabilities #2868
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What this PR does / why we need it:
Fails the build process if we find critical vulnerabilities.
Not sure about this. Could block a release but do we want a release that has known critical vulns?
We could also add a switch the says that they can be ignored if there is not a fix yet but thats terrible IMHO because we would be releasing something that its indeed broken
This would fail builds on MASTER and RELEASE pipelines only, which makes sense to me. Between a PR and a master/release build there can be updates to packages and so on, so we dont have the control there and should not block a PR. But on release and master we can be informed about it and block a release or send and advisor or backport stuff/rebuild.