docs(security): name the current Opengrep default in the SAST table - #466
Conversation
netresearch/typo3-ci-workflows#269 changed the default opengrep-config of security.yml to `--config auto --error --severity WARNING --severity ERROR`. The Enforced-by cell still named `--error --severity WARNING`, which selected only WARNING rules, so ERROR findings did not fail the check the row describes. The rule text "severity WARNING or higher" is now accurate and stays unchanged. Assisted-by: claude-code:claude-opus-5-5 Agent-Session: https://claude.ai/code/session_012wvC6mH5CGkQr6HUcoUX2J Agent-Host: 0493f0 Signed-off-by: Sebastian Mendel <sebastian.mendel@netresearch.de>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe Opengrep enforcement entry now lists Priority: ⬇️ Low Change: Other Merge Risk: ⚪ Minimal · up to The SAST enforcement documentation matches the shared workflow’s stated defaults; no actionable merge risk remains. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The documented arguments exactly match the merged reusable workflow default.
Review effort: Balanced
Findings: None
What changed in this PR
Updates the SAST policy documentation to match the current shared Opengrep workflow default.
Changes:
- Documents that WARNING and ERROR findings block CI.
- Adds the default
opengrep-configarguments.
| File | Description |
|---|---|
SECURITY.md |
Corrects the Opengrep enforcement configuration. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.



Merging this makes the Opengrep row of the SAST table in
SECURITY.mdname the current default arguments oftypo3-ci-workflowssecurity.yml. The cell still named--error --severity WARNING, which selected only WARNING rules.Changes
opengrep-configofsecurity.ymlto--config auto --error --severity WARNING --severity ERROR, so Opengrep now fails on ERROR findings as well as WARNING. No workflow in this repository overridesopengrep-config.SECURITY.md, table Static analysis (SAST): the Enforced-by cell now names the defaultopengrep-config,--config auto --error --severity WARNING --severity ERROR. The rule text "severity WARNING or higher" is accurate again and is unchanged, as is the#static-analysis-sastheading that consumer repositories link to.Checks run
SECURITY.md: 0 issues.security.ymlamong the 70 repositories of the OpenSSF sweep passesopengrep-config(grep of.github/workflowsat each default branch).Assisted by claude-code:claude-opus-5-5 — Session