Skip to content

Guardrails

security ​

4 guardrails, all at version v1.

GuardrailDefault severityWhat it checks
security/finding-budgetwarningThe number of findings at or above a severity stays within the budget the team set, so a report too long to read doesn't pass as a clean one.
security/fixable-vulnerabilitieswarningEvery finding the scanner reported a fixed version for has had that fix applied, so the findings that only need an upgrade, not a redesign, aren't left open.
security/no-high-findingserrorEvery finding the scanner reported is below the severity the team gates on.
security/scan-results-presenterrorA scanner ran and left a report the build can be judged on, instead of the build reporting nothing at all.

Shared collectors ​

Every security guardrail receives the facts these collectors gather. Individual guardrails can ask for more collectors of their own.

CollectorGathers
scanFindings from whatever scanner the build already ran, read from the report it left behind and normalized into one shape, whether the tool was a SAST, an SCA, a secret detector or an infrastructure scanner.

You configure every guardrail in this category the same way, in the guardrails.checks array of buildnote.json. Configuring guardrails lists every option, and Guardrails lets you search the whole library.

Buildnote Limited
Registered in England and Wales, Reg: 16140412