-
Notifications
You must be signed in to change notification settings - Fork 37
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
rule tuning: make severities more appropriate #510
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nice!
Would you mind looking at wolfi-dev/os#30457?
The gitaly
binary is 252MB and 66MB after being compressed which is still pretty large.
Would it make sense to tune the linux_multi_persist
rule to high or just add a quick override rule for that binary?
Co-authored-by: Evan Gibler <[email protected]> Signed-off-by: Thomas Strömberg <[email protected]>
gitaly looks interesting.
For now, I think the rule should hit rare enough that we should do overrides; assuming the binary we are looking at isn't doing anything bad. |
Indeed. AFAIK none of the previous releases triggered that rule. Update -- investigation is here: wolfi-dev/os#30457 (comment) I'll open a PR for an override rule. |
risk tuning, mostly relating to "HIGH" findings in Wolfi.
Add/fix testdata missing for clean Linux files.