Skip to content

Guardrails / supply-chain

No critical vulnerabilities in dependencies ​

supply-chain/no-critical-vulnerabilities@v1

No dependency of the build has an open finding at or above the severity the team gates on.

Idsupply-chain/no-critical-vulnerabilities
Versionv1
Categorysupply-chain
Default severityerror
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsscan

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
scanFindings from whatever scanner the build already ran, read from the report it left behind and normalized into one shape, whether the tool was a SAST, an SCA, a secret detector or an infrastructure scanner.none

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "supply-chain/no-critical-vulnerabilities@v1",
              "severity": "error",
              "with": {
                  "severity": "critical",
                  "ignore": ""
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
severityLowest severity that violates: critical, high, medium, low or info.criticalGUARDRAIL_INPUT_SEVERITY
ignoreComma separated vulnerability identifiers to leave out, for findings already accepted. Someone should be able to explain each one.``GUARDRAIL_INPUT_IGNORE

How to fix ​

Upgrade the dependency to the version the scanner reports as fixed. If no fix exists, record a risk acceptance with an owner and an expiry date where the exception register can see it, instead of raising the threshold.

Run the scanner in the pipeline and leave its report in the workspace:

bash
trivy fs --format json --output trivy.json .

More in supply-chain ​

All 6 supply-chain guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412