Skip to content

Guardrails / security

The build produced a security scan ​

security/scan-results-present@v1

A scanner ran and left a report the build can be judged on, instead of the build reporting nothing at all.

Idsecurity/scan-results-present
Versionv1
Categorysecurity
Default severityerror
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsscan

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
scanFindings from whatever scanner the build already ran, read from the report it left behind and normalized into one shape, whether the tool was a SAST, an SCA, a secret detector or an infrastructure scanner.none

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "security/scan-results-present@v1",
              "severity": "error",
              "with": {},
              "exemptions": []
          }
      ]
  }
}

How to fix ​

Run a scanner in the pipeline and leave its report in the workspace before buildnote guardrails runs. Any of these works:

bash
semgrep --config auto --sarif --output semgrep.sarif
trivy fs --format json --output trivy.json .
grype dir:. -o json --file grype.json

The guardrail reads whatever report it finds, so you can use any scanner. A missing report is the violation: you can't show that a build nobody scanned is clean.

More in security ​

  • security/finding-budget. The number of findings at or above a severity stays within the budget the team set, so a report too long to read doesn't pass as a clean one.
  • security/fixable-vulnerabilities. Every finding the scanner reported a fixed version for has had that fix applied, so the findings that only need an upgrade, not a redesign, aren't left open.
  • security/no-high-findings. Every finding the scanner reported is below the severity the team gates on.

All 4 security guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412