Skip to content

Set severity when output is sarif#336

Open
austimkelly wants to merge 3 commits intoaquasecurity:masterfrom
austimkelly:sarif-severity
Open

Set severity when output is sarif#336
austimkelly wants to merge 3 commits intoaquasecurity:masterfrom
austimkelly:sarif-severity

Conversation

@austimkelly
Copy link

Before this fix the --severity flag and values were not added to the sarif input. Hence, when a default value of 'CRITICAL,HIGH' was supplied, it would simply be ignored and report everything. The result is producing a bunch of noisy alerts, and anin't nobody got time for that!

Before the fix:
sarif-no-severity-on-main

with this PR fix:
austimkelly-severity-sarif-fix

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant