Skip to content

LAB - GHA#1

Open
endor-lmoreno wants to merge 10 commits intomainfrom
experiment_findings_evaluation_gha
Open

LAB - GHA#1
endor-lmoreno wants to merge 10 commits intomainfrom
experiment_findings_evaluation_gha

Conversation

@endor-lmoreno
Copy link
Contributor

No description provided.

@endor-lmoreno endor-lmoreno force-pushed the experiment_findings_evaluation_gha branch 2 times, most recently from 366e9f6 to 8a4b371 Compare February 5, 2026 21:19
@endor-lmoreno endor-lmoreno force-pushed the experiment_findings_evaluation_gha branch from 8a4b371 to 8ba5a34 Compare February 5, 2026 21:24
@github-actions
Copy link

github-actions bot commented Feb 5, 2026

Warning

Endor Labs detected 1 policy violations associated with this pull request.

Please review the findings that caused the policy violations.

📋 Policy: Vulnerabilities (1 finding)

📥 Package mvn://com.endor.webapp:endor-java-webapp-demo@4.0-SNAPSHOT

⤵️ Dependency: mvn://commons-lang:commons-lang@2.6
🚩 GHSA-j288-q9x7-2f5v: Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs

Details

  • Severity: Medium
  • Tags: Direct Normal Potentially Reachable Dependency Potentially Reachable Function Unfixable Blocker
  • Categories: SCA Vulnerability Security
  • Remediation: No patch upgrades available to fix the issue. Check the security advisory for alternative controls or actions.

This comment was automatically generated by Endor Labs.
Scanned @ 02-06-2026 14:41:17 UTC

@endor-lmoreno endor-lmoreno force-pushed the experiment_findings_evaluation_gha branch 4 times, most recently from 4971e23 to 99b97af Compare February 5, 2026 22:19
@endor-lmoreno endor-lmoreno force-pushed the experiment_findings_evaluation_gha branch from 99b97af to af0cd47 Compare February 6, 2026 01:48
Update GitHub Actions workflow to read allowed vulnerability aliases from a new .trivyignore file at the repo root. The script now supports full-line and inline '#' comments, trims whitespace, ignores blank lines, and prints the parsed allowlist; it also handles a missing file gracefully. Matching logic was fixed to correctly check aliases against a bash array. Add example .trivyignore entries including comment usage.
@endor-lmoreno endor-lmoreno force-pushed the experiment_findings_evaluation_gha branch from 62905bd to 2654a44 Compare February 6, 2026 02:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant