Skip to content

docs(security): name the current Opengrep default in the SAST table - #466

Merged
CybotTM merged 1 commit into
mainfrom
docs/opengrep-severity-wording
Oct 1, 2026
Merged

CybotTM merged 1 commit into
mainfrom
docs/opengrep-severity-wording

Conversation

@CybotTM

@CybotTM CybotTM commented Oct 1, 2026

Copy link
Copy Markdown
Member

Merging this makes the Opengrep row of the SAST table in SECURITY.md name the current default arguments of typo3-ci-workflows security.yml. The cell still named --error --severity WARNING, which selected only WARNING rules.

Changes

  • netresearch/typo3-ci-workflows#269 changed the default opengrep-config of security.yml to --config auto --error --severity WARNING --severity ERROR, so Opengrep now fails on ERROR findings as well as WARNING. No workflow in this repository overrides opengrep-config.
  • SECURITY.md, table Static analysis (SAST): the Enforced-by cell now names the default opengrep-config, --config auto --error --severity WARNING --severity ERROR. The rule text "severity WARNING or higher" is accurate again and is unchanged, as is the #static-analysis-sast heading that consumer repositories link to.

Checks run

  • markdownlint-cli2 on SECURITY.md: 0 issues.
  • Fleet check: no caller of security.yml among the 70 repositories of the OpenSSF sweep passes opengrep-config (grep of .github/workflows at each default branch).

Assisted by claude-code:claude-opus-5-5 — Session

netresearch/typo3-ci-workflows#269 changed the default opengrep-config of
security.yml to `--config auto --error --severity WARNING --severity
ERROR`. The Enforced-by cell still named `--error --severity WARNING`,
which selected only WARNING rules, so ERROR findings did not fail the
check the row describes. The rule text "severity WARNING or higher" is
now accurate and stays unchanged.

Assisted-by: claude-code:claude-opus-5-5
Agent-Session: https://claude.ai/code/session_012wvC6mH5CGkQr6HUcoUX2J
Agent-Host: 0493f0
Signed-off-by: Sebastian Mendel <sebastian.mendel@netresearch.de>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 9c9708c6-fa99-4fb5-8174-f290dfc1977b

📥 Commits

Reviewing files that changed from the base of the PR and between 19c8b84 and 1db5346.

📒 Files selected for processing (1)
  • SECURITY.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The Opengrep enforcement entry now lists --config auto --error --severity WARNING --severity ERROR as its default options.

Priority: ⬇️ Low

Change: Other

Merge Risk: ⚪ Minimal · up to 1db53

The SAST enforcement documentation matches the shared workflow’s stated defaults; no actionable merge risk remains.

Architecture Summary

Architecture risk: 🔵 Low · up to 1db53

The change affects 1 system.

Changed systems: SECURITY.md

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — SECURITY.md (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in SECURITY.md: The Opengrep enforcement entry adds the default --config auto setting and explicitly includes --severity ERROR alongside the existing warning threshold.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the documentation change and the updated Opengrep default. It accurately summarizes the main change.
Description check ✅ Passed The description clearly explains the reason for the change, the affected file and table, the related workflow change, and the validation performed. It does not use the template's Type of Change or Che…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
✨ Simplify code
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

@CybotTM
CybotTM marked this pull request as ready for review October 1, 2026 06:50
Copilot AI balanced review requested due to automatic review settings October 1, 2026 06:50

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documented arguments exactly match the merged reusable workflow default.

Review effort: Balanced
Findings: None

What changed in this PR

Updates the SAST policy documentation to match the current shared Opengrep workflow default.

Changes:

  • Documents that WARNING and ERROR findings block CI.
  • Adds the default opengrep-config arguments.
File Description
SECURITY.md Corrects the Opengrep enforcement configuration.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@CybotTM
CybotTM merged commit d3aad4c into main Oct 1, 2026
14 checks passed
@CybotTM
CybotTM deleted the docs/opengrep-severity-wording branch October 1, 2026 06:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants