Skip to content

ci: drop adoption grace — run the osv lane at hard-fail - #36

Merged
bdelanghe merged 1 commit into
mainfrom
claude/deps-hard-fail
Jul 30, 2026
Merged

ci: drop adoption grace — run the osv lane at hard-fail#36
bdelanghe merged 1 commit into
mainfrom
claude/deps-hard-fail

Conversation

@bdelanghe

Copy link
Copy Markdown
Contributor

Fleet-wide grace sweep — ci-workflows#8.

report-only: true was adoption grace so a pre-existing advisory couldn't block instrumentation. Temporary by design, but with no expiry or owner a repo left holding it shows a green check that gates nothing.

Self-verifying: if this repo still has a finding, this PR's own osv check goes red and it isn't merged. Green means genuinely clean at hard-fail.


Generated by Claude Code

The report-only flag was adoption grace so a pre-existing advisory could not
block instrumentation. It was always meant to be temporary, and it has no expiry
or owner, so a repo left holding it shows a green check that gates nothing.

This repo's scan is clean, so grace comes off: a known vulnerability now reds the
lane, which is the template's intended steady state.

Self-verifying by construction — if this repo did still carry a finding, this
PR's own osv check goes red and it does not get merged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@bdelanghe
bdelanghe merged commit 2d02ee3 into main Jul 30, 2026
8 checks passed
@github-project-automation github-project-automation Bot moved this from Todo to Done in Front Desk Jul 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant