You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The current rules in the exported Sarif file do not include the security-severity property. A per the docs below, this is recommended for security rules.
oliverchang
added
backlog
Important but currently unprioritized
and removed
stale
The issue or PR is stale and pending automated closure
labels
Aug 6, 2024
The current rules in the exported Sarif file do not include the security-severity property. A per the docs below, this is recommended for security rules.
https://docs.github.com/en/code-security/code-scanning/integrating-with-code-scanning/sarif-support-for-code-scanning#reportingdescriptor-object
Likewise, the precision property is also recommended and used in concert with the security severity to assess the impact of the recorded CVE's.
The text was updated successfully, but these errors were encountered: