Skip to content

chore(security): block merge on high-severity scanner findings - #10

Merged
abir-vim merged 1 commit into
mainfrom
chore/scanner-block-on-high
Jul 28, 2026
Merged

chore(security): block merge on high-severity scanner findings#10
abir-vim merged 1 commit into
mainfrom
chore/scanner-block-on-high

Conversation

@abir-vim

Copy link
Copy Markdown
Collaborator

Automated fleet sync of the org security scanner. Raises BLOCK_ON_SEVERITY from critical to high so high and critical findings (and dependency BLOCK) fail the AI security scan check. Medium/low/info remain advisory. See scanner-org for the source template.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jul 28, 2026

Copy link
Copy Markdown

Deploying theme-editor-deploy with  Cloudflare Pages  Cloudflare Pages

Latest commit: 910b04d
Status: ✅  Deploy successful!
Preview URL: https://bbf2d4ba.theme-editor-deploy.pages.dev
Branch Preview URL: https://chore-scanner-block-on-high.theme-editor-deploy.pages.dev

View logs

@github-actions

Copy link
Copy Markdown

Security Scanner Results

Critical High Medium Low Info Dep BLOCK Dep WARN
0 0 0 0 1 0 0

Findings

  • Security gate block threshold lowered from 'critical' to 'high'.github/workflows/security.yml:417
    • Remediation: No fix required — this is an intentional hardening of the security gate. Ensure the team is aware that high-severity findings will now block merges, and that any legitimate high findings are triaged/resolved rather than the threshold being reverted.

Gate blocks at severity high or a dependency marked BLOCK. Full history in scanner-stats.

@abir-vim
abir-vim merged commit 969bccd into main Jul 28, 2026
4 checks passed
@abir-vim
abir-vim deleted the chore/scanner-block-on-high branch July 28, 2026 10:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant