Adarsh-Me commented on issue #825:
URL: https://github.com/apache/celix/issues/825#issuecomment-6035919744

   @pnoltes yes - SARIF is not code-only: it is a generic findings envelope, 
and Trivy's `--format sarif` covers vulnerability results (its docs matrix 
lists vuln/misconfig/secret/license). One caveat from SECURITY.md: I would keep 
output artifact-only rather than upload to the security tab, since an 
undisclosed flaw must not be published. Agreed that #845 is the input here.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to