Using Security Severities (Critical, High, Medium, Low) for SARIF out put #7256
Unanswered
HuijinLiuInforma
asked this question in
Show and tell
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Currently SARIF out put for GitHub using Error, Warning, Notes for alert. The development team ignored Critical, High risk issues, because those issues are marked as "Error". Help to add one section in SARIF output file please. Example:
properties: {
"precision": "very-high",
"security-severity": "9.1",
"tags": ["vulnerability","security","CRITICAL"]
}
See Checkmarx/kics-github-action#99 for details.
Beta Was this translation helpful? Give feedback.
All reactions