security
4 guardrails, all at version v1.
| Guardrail | Default severity | What it checks |
|---|---|---|
security/finding-budget | warning | The number of findings at or above a severity stays within the budget the team set, so a report too long to read doesn't pass as a clean one. |
security/fixable-vulnerabilities | warning | Every finding the scanner reported a fixed version for has had that fix applied, so the findings that only need an upgrade, not a redesign, aren't left open. |
security/no-high-findings | error | Every finding the scanner reported is below the severity the team gates on. |
security/scan-results-present | error | A scanner ran and left a report the build can be judged on, instead of the build reporting nothing at all. |
Shared collectors
Every security guardrail receives the facts these collectors gather. Individual guardrails can ask for more collectors of their own.
| Collector | Gathers |
|---|---|
scan | Findings from whatever scanner the build already ran, read from the report it left behind and normalized into one shape, whether the tool was a SAST, an SCA, a secret detector or an infrastructure scanner. |
You configure every guardrail in this category the same way, in the guardrails.checks array of buildnote.json. Configuring guardrails lists every option, and Guardrails lets you search the whole library.