feat: reduce noise from vulnerability scanning - #1440
Conversation
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
✅
|
| Descriptor | Linter | Files | Fixed | Errors | Max errors | Warnings | Elapsed time |
|---|---|---|---|---|---|---|---|
| ✅ ACTION | actionlint | 23 | 0 | 0 | 0.27s | ||
| ✅ DOCKERFILE | hadolint | 4 | 0 | 0 | 0.37s | ||
| ✅ JSON | npm-package-json-lint | yes | no | no | 0.55s | ||
| ✅ JSON | prettier | 45 | 8 | 0 | 0 | 1.03s | |
| ✅ JSON | v8r | 45 | 0 | 0 | 12.28s | ||
| markdownlint | 14 | 0 | 3 | 0 | 1.13s | ||
| ✅ MARKDOWN | markdown-table-formatter | 14 | 0 | 0 | 0 | 0.27s | |
| ✅ REPOSITORY | betterleaks | yes | no | no | 2.24s | ||
| ✅ REPOSITORY | checkov | yes | no | no | 22.72s | ||
| ✅ REPOSITORY | git_diff | yes | no | no | 0.02s | ||
| ✅ REPOSITORY | grype | yes | no | no | 76.71s | ||
| osv-scanner | yes | 2 | no | 1.55s | |||
| ✅ REPOSITORY | secretlint | yes | no | no | 2.52s | ||
| ✅ REPOSITORY | syft | yes | no | no | 6.72s | ||
| ✅ REPOSITORY | trivy | yes | no | no | 12.79s | ||
| ✅ REPOSITORY | trivy-sbom | yes | no | no | 0.33s | ||
| ✅ REPOSITORY | trufflehog | yes | no | no | 3.61s | ||
| lychee | 118 | 1 | 0 | 8.54s | |||
| ✅ YAML | prettier | 36 | 0 | 0 | 0 | 3.4s | |
| ✅ YAML | v8r | 36 | 0 | 0 | 10.27s | ||
| ✅ YAML | yamllint | 36 | 0 | 0 | 1.14s |
Detailed Issues
⚠️ SPELL / lychee - 1 error
📝 Summary
---------------------
🔍 Total..........160
🔗 Unique.........132
✅ Successful.....154
⏳ Timeouts.........0
🔀 Redirected......21
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors...........1
⛔ Unsupported......1
Errors in .github/TOOL_VERSION_ISSUE_TEMPLATE.md
[403] https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads (at 38:7) | Rejected status code: 403 Forbidden
Hint: Followed 21 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ MARKDOWN / markdownlint - 3 errors
docs/adr/0001-vulnerability-scanning-noise-reduction.md:9:401 error MD013/line-length Line length [Expected: 400; Actual: 450]
docs/adr/0001-vulnerability-scanning-noise-reduction.md:36:401 error MD013/line-length Line length [Expected: 400; Actual: 540]
docs/adr/0001-vulnerability-scanning-noise-reduction.md:38:401 error MD013/line-length Line length [Expected: 400; Actual: 423]
⚠️ REPOSITORY / osv-scanner - 2 errors
Scanning dir .
Starting filesystem walk for root: /
Scanned .devcontainer/cpp/requirements.txt file and found 20 packages
Scanned .devcontainer/docs/requirements.txt file and found 14 packages
Scanned package-lock.json file and found 73 packages
Scanned test/embedded-rust/workspace/cortex-mf/Cargo.lock file and found 20 packages
Scanned test/embedded-rust/workspace/cortex-m/Cargo.lock file and found 20 packages
Scanned test/rust/workspace/cargo/Cargo.lock file and found 1 package
Scanned test/rust/workspace/clippy/Cargo.lock file and found 1 package
Scanned test/rust/workspace/test/Cargo.lock file and found 1 package
End status: 83 dirs visited, 280 inodes visited, 8 Extract calls, 72.094291ms elapsed, 72.094531ms wall time
Total 3 packages affected by 4 known vulnerabilities (0 Critical, 2 High, 0 Medium, 0 Low, 2 Unknown) from 2 ecosystems.
2 vulnerabilities can be fixed.
+-------------------------------------+------+-----------+-----------------------+---------+---------------+---------------------------------------------------+
| OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+---------------------------------------------------+
| https://osv.dev/RUSTSEC-2026-0110 | | crates.io | bare-metal | 0.2.5 | -- | test/embedded-rust/workspace/cortex-m/Cargo.lock |
| https://osv.dev/RUSTSEC-2026-0110 | | crates.io | bare-metal | 0.2.5 | -- | test/embedded-rust/workspace/cortex-mf/Cargo.lock |
| https://osv.dev/GHSA-mh99-v99m-4gvg | 7.5 | npm | brace-expansion (dev) | 5.0.7 | 5.0.8 | package-lock.json |
| https://osv.dev/GHSA-rgw5-rvv9-x895 | 7.5 | npm | brace-expansion (dev) | 5.0.7 | 5.0.9 | package-lock.json |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+---------------------------------------------------+
See detailed reports in MegaLinter artifacts
You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:
- oxsecurity/megalinter/flavors/salesforce@v10.0.0 (57 linters)
- oxsecurity/megalinter/flavors/javascript@v10.0.0 (62 linters)
Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)
- Documentation: Custom Flavors
- Command:
npx mega-linter-runner@10.0.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,DOCKERFILE_HADOLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

Show us your support by starring ⭐ the repository
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|



🚀 Hey, I have created a Pull Request
Description of changes
This pull request introduces a comprehensive noise-reduction strategy for vulnerability scanning, aiming to ensure that only actionable and relevant findings are surfaced to maintainers. The changes filter out vulnerabilities with no available fixes and kernel-package CVEs that cannot be exploited in containers, and document this approach for transparency and future review. Both Trivy scanners (in CI and MegaLinter) are updated to apply these filters consistently.
Vulnerability scanning noise reduction:
.github/linters/kernel-findings.rego) to suppress all findings for packages whose names start withlinux-, as kernel packages cannot be exploited inside containers..github/workflows/vulnerability-scan.ymlto:ignore_unfixed: trueto suppress vulnerabilities without upstream fixes.TRIVY_IGNORE_POLICYenvironment variable.MegaLinter configuration:
.mega-linter.ymlto pass both--ignore-unfixedand the new Rego policy to Trivy, ensuring consistent filtering in repository scans.Documentation:
docs/adr/0001-vulnerability-scanning-noise-reduction.md) detailing the rationale, implementation, and implications of the noise-reduction approach for vulnerability scanning.✔️ Checklist