Skip to content

Guardrails / security

Scanner findings sit within the budget ​

security/finding-budget@v1

The number of findings at or above a severity stays within the budget the team set, so a report too long to read doesn't pass as a clean one.

Idsecurity/finding-budget
Versionv1
Categorysecurity
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsscan

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
scanFindings from whatever scanner the build already ran, read from the report it left behind and normalized into one shape, whether the tool was a SAST, an SCA, a secret detector or an infrastructure scanner.none

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "security/finding-budget@v1",
              "severity": "warning",
              "with": {
                  "severity": "medium",
                  "budget": "25",
                  "kinds": "sast,sca,iac,container,secret"
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
severityLowest severity that counts against the budget: critical, high, medium, low or info.mediumGUARDRAIL_INPUT_SEVERITY
budgetMaximum number of findings at or above that severity the build may have.25GUARDRAIL_INPUT_BUDGET
kindsComma separated kinds of finding that are counted, as the collector normalises them: sast, sca, secret, iac, container, unknown.sast,sca,iac,container,secretGUARDRAIL_INPUT_KINDS

How to fix ​

Reduce the count, or change the budget deliberately and record why. The point is to bring the number down: a budget that is raised every time it's exceeded measures nothing.

security/no-high-findings gates what must never ship. This guardrail covers what accumulates below that line, which is where scanner findings pile up when nobody tracks a number. Nobody triages a list of five hundred medium findings, and the one that matters is somewhere in it.

More in security ​

  • security/fixable-vulnerabilities. Every finding the scanner reported a fixed version for has had that fix applied, so the findings that only need an upgrade, not a redesign, aren't left open.
  • security/no-high-findings. Every finding the scanner reported is below the severity the team gates on.
  • security/scan-results-present. A scanner ran and left a report the build can be judged on, instead of the build reporting nothing at all.

All 4 security guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412