Skip to content

RFP.2.2 demo: severity gate — blocks on Critical & High#3

Open
dave-apisec wants to merge 11 commits into
developfrom
demo/scan-block-high
Open

RFP.2.2 demo: severity gate — blocks on Critical & High#3
dave-apisec wants to merge 11 commits into
developfrom
demo/scan-block-high

Conversation

@dave-apisec

Copy link
Copy Markdown
Owner

PR-triggered APIsec scan with blocking gate on Critical & High severity findings (APISEC_MAX_CRITICAL=0, APISEC_MAX_HIGH=0).

Demonstrates RFP.2.1 + RFP.2.2 — PR-triggered scan, runner isolation,
secret-based credential handling, and severity gating:
  - APISEC_MAX_HIGH: "0"  → any High finding blocks the PR
  - Medium advisory runs with continue-on-error (warns, does not block)
Tightens RFP.2.2 demo to a single blocking step: APISEC_MAX_CRITICAL=0
and APISEC_MAX_HIGH=0. Container exits non-zero on any Critical or High
finding, which fails the check and prevents merge.
@github-actions

Copy link
Copy Markdown

APIsec API Security Scan

Severity Gate Result
🔴 Critical / High (blocking) BLOCKED — resolve findings before merging

View scan results in APIsec →

This PR is blocked from merging. Resolve all Critical and High severity findings and re-run the scan.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant