As Daniel wrote, please create a Jira task. Example: https://issues.jenkins-ci.org/browse/INFRA-2768 <https://issues.jenkins-ci.org/browse/INFRA-2768>
> Am 12.10.2020 um 10:59 schrieb tzach solomon <[email protected]>: > > Hi Daniel, > > Thank you for this one. > How can I register the plugin https://plugins.jenkins.io/bitbucket/ > <https://plugins.jenkins.io/bitbucket/> for the security scans? > > Thanks, > Tzach > > On Fri, Oct 9, 2020 at 9:00 PM Daniel Beck <[email protected] > <mailto:[email protected]>> wrote: > Hi everyone, > > GitHub announced last week that their code scanning functionality is now > generally available[1]. > > The Jenkins security team has worked on queries specifically for Jenkins and > Jenkins plugins. > > I'd now like to share them with a limited audience to get some initial > feedback before we start rolling them out more widely. > > If you're interested in getting your plugin code scanned and the results to > appear on the GitHub UI, please file an issue in the Jenkins Jira INFRA > project for the 'github' component with a list of plugins/repos you're > maintaining and would like code scanning result to be reported to. I > encourage all maintainers to sign up for this. I think the findings are > generally reasonably high quality, and even if not, the GitHub UI makes it > really easy to hide irrelevant warnings. > > Please note we're only scanning the default branch (typically 'master'), and > only in irregular intervals. Future enhancements could integrate this with > pull requests, and to happen on every commit on certain branches, but this is > all still very new. > > For now our queries aren't accessible publicly. If you're a regular > contributor to Jenkins and interested in contributing to these > Jenkins-specific code scanning queries, please reach out to me directly. > > > 1: https://github.blog/2020-09-30-code-scanning-is-now-available/ > <https://github.blog/2020-09-30-code-scanning-is-now-available/> > > -- > You received this message because you are subscribed to the Google Groups > "Jenkins Developers" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected] > <mailto:jenkinsci-dev%[email protected]>. > To view this discussion on the web visit > https://groups.google.com/d/msgid/jenkinsci-dev/63EFC305-9466-4DBF-B38E-9B9730705732%40beckweb.net > > <https://groups.google.com/d/msgid/jenkinsci-dev/63EFC305-9466-4DBF-B38E-9B9730705732%40beckweb.net>. > > -- > You received this message because you are subscribed to the Google Groups > "Jenkins Developers" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected] > <mailto:[email protected]>. > To view this discussion on the web visit > https://groups.google.com/d/msgid/jenkinsci-dev/CAC19wgKLM1MgKCNsO-NRJ42Ej9fEk79v8tz960eqKnJ5t_ZMAQ%40mail.gmail.com > > <https://groups.google.com/d/msgid/jenkinsci-dev/CAC19wgKLM1MgKCNsO-NRJ42Ej9fEk79v8tz960eqKnJ5t_ZMAQ%40mail.gmail.com?utm_medium=email&utm_source=footer>. -- You received this message because you are subscribed to the Google Groups "Jenkins Developers" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/jenkinsci-dev/7BE0BF41-A9FB-481B-B4F6-A7D0DD6D1788%40gmail.com.
