Skip to content

ci(root): address review comments on osv-scanner migration#9302

Closed
roshan-bitgo wants to merge 1 commit into
fix/migrate-to-osv-scannerfrom
fix/osv-scanner-review-comments
Closed

ci(root): address review comments on osv-scanner migration#9302
roshan-bitgo wants to merge 1 commit into
fix/migrate-to-osv-scannerfrom
fix/osv-scanner-review-comments

Conversation

@roshan-bitgo

Copy link
Copy Markdown
Contributor

Stacks on #9263.

Addresses the three review comments left on the migration PR:

  • Remove leftover Install retry step from npmjs-release.yml — only needed for the old improved-yarn-audit invocation; publish.yml already dropped it
  • Fix stale branch_prefix in iyarc-prune.yml: iyarc-prune/osv-scanner-prune/ to match the renamed agent file
  • Expand osv-scanner.toml exclusion reasons with full context preserved from the deleted .iyarc file

Closes VL-7134 (via #9263).

- Remove leftover Install retry step from npmjs-release.yml (the retry
  binary was only needed for the old improved-yarn-audit invocation;
  publish.yml correctly dropped it when switching to osv-scanner-action)
- Fix stale branch_prefix in iyarc-prune.yml: iyarc-prune/ ->
  osv-scanner-prune/ to match the renamed agent file
- Expand osv-scanner.toml exclusion reasons to preserve context from
  the deleted .iyarc file (transitive dep paths, risk profiles,
  mitigations)

TICKET: VL-7134
@linear-code

linear-code Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

VL-7134

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant