Board: yes
Security and quality alerts are worked before any phase, one issue per class of alert (the rule of 2026-09-05 on steinbruch, fleet-wide since 2026-09-06). This is the class SASTID from code-scanning, 1 open alert, the highest severity medium.
What the class says
Determines if the project uses static code analysis.
The alerts
Done when
- This class stands at zero open alerts on the Security tab: every alert repaired by a change that lands here, or dismissed with a reason written on this issue that names the predicate, pasted from the API rather than clicked.
- The planning issue for this class on the operations tracker, which asks how the class is kept from arriving again, is named here; nothing here waits on it.
Scope: .github/workflows
Board: yes
Security and quality alerts are worked before any phase, one issue per class of alert (the rule of 2026-09-05 on steinbruch, fleet-wide since 2026-09-06). This is the class
SASTIDfrom code-scanning, 1 open alert, the highest severity medium.What the class says
Determines if the project uses static code analysis.
The alerts
no file associated with this alert:1: https://github.com/Flowfin/core/security/code-scanning/2Done when
Scope: .github/workflows