Skip to content

ci(root): address review comments on osv-scanner migration#9307

Merged
roshan-bitgo merged 1 commit into
masterfrom
fix/osv-scanner-review-comments
Jul 21, 2026
Merged

ci(root): address review comments on osv-scanner migration#9307
roshan-bitgo merged 1 commit into
masterfrom
fix/osv-scanner-review-comments

Conversation

@roshan-bitgo

Copy link
Copy Markdown
Contributor

Stacks on #9263.

Addresses the three review comments left on the migration PR:

  • Remove leftover Install retry step from npmjs-release.yml — only needed for the old improved-yarn-audit invocation; publish.yml already dropped it
  • Fix stale branch_prefix in iyarc-prune.yml: iyarc-prune/osv-scanner-prune/ to match the renamed agent file
  • Expand osv-scanner.toml exclusion reasons with full context preserved from the deleted .iyarc file

Closes VL-7134 (via #9263).

- Remove leftover Install retry step from npmjs-release.yml (the retry
  binary was only needed for the old improved-yarn-audit invocation;
  publish.yml correctly dropped it when switching to osv-scanner-action)
- Fix stale branch_prefix in iyarc-prune.yml: iyarc-prune/ ->
  osv-scanner-prune/ to match the renamed agent file
- Expand osv-scanner.toml exclusion reasons to preserve context from
  the deleted .iyarc file (transitive dep paths, risk profiles,
  mitigations)

TICKET: VL-7134
@linear-code

linear-code Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

VL-7134

@roshan-bitgo
roshan-bitgo marked this pull request as ready for review July 21, 2026 09:29
@roshan-bitgo
roshan-bitgo requested review from a team as code owners July 21, 2026 09:29
@roshan-bitgo
roshan-bitgo merged commit 0815528 into master Jul 21, 2026
23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants