You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
# - extract numeric scores for CVSS types (cvss_v3 or numeric severity[].score)
58
-
# - compare to threshold
59
-
if jq '
60
-
.results[]
61
-
| .packages[]?
62
-
| .vulnerabilities[]?
63
-
| ( .severity[]?.score // "" ) as $s
64
-
| select($s != "")
65
-
| ($s | tonumber) >= 4.0
66
-
' "${RUNNER_TEMP}/results.json" | grep -q -e . ; then
54
+
# Each rule in the SARIF report is a vulnerability found by the scan,
55
+
# with its worst numeric CVSS score in the security-severity property.
56
+
# A jq failure (e.g. missing or malformed report) aborts the step via
57
+
# set -e instead of being mistaken for "no vulnerabilities".
58
+
count="$(jq '
59
+
[ .runs[].tool.driver.rules[]?
60
+
| .properties["security-severity"] // empty
61
+
| tonumber
62
+
| select(. >= 4.0) ]
63
+
| length
64
+
' "${RUNNER_TEMP}/osv/results.sarif")"
65
+
if [ "${count}" -gt 0 ]; then
67
66
>&2 echo "error: found one or more vulnerabilities with a medium or higher severity (see step 'scan > osv-scanner > Run osv-scanner-reporter' for details)"
0 commit comments