mirror of
https://github.com/semantica-agi/semantica.git
synced 2026-09-10 04:00:35 +00:00
Qodo caught a real gap on this PR: the jq-based exclusion I added only covers the CI gate (the VULNS count and the failure-path detail print). The "Comment PR with Security Results" step reads safety-report.json independently in its own JS, with no filtering at all, so a PR touching only the accepted cuda-toolkit CVE would still get a comment saying "Found 1" even though the gate itself correctly treats it as non-actionable and passes. Export IGNORED_VULN_IDS via $GITHUB_ENV from the shell step so the JS step can read the same list, and filter data.vulnerabilities there before rendering - with a footnote naming what was excluded and why, so the comment stays transparent about the accepted finding rather than just silently hiding it. Verified the JS logic standalone against two synthetic reports: one with the accepted CVE plus an unrelated real one (shows only the real one, plus the footnote), and one with only the accepted CVE (shows "No findings" plus the footnote, rather than misleadingly looking identical to a clean scan with no explanation).