Skip to content

Docs/findings quality evidence roadmap#263

Merged
hello-args merged 5 commits into
developfrom
docs/findings-quality-evidence-roadmap
Jun 13, 2026
Merged

Docs/findings quality evidence roadmap#263
hello-args merged 5 commits into
developfrom
docs/findings-quality-evidence-roadmap

Conversation

@hello-args

Copy link
Copy Markdown
Collaborator

The Validate Action failure was a mismatch between the new action default and the smoke test target.

What broke: action/action.yml now defaults ci-trust to true, which adds --ci-trust (enforce mode, min-score 70, fail-on-critical). The validate workflow scans examples/vulnerable-mcp-server/server.py and only set fail-on-critical: "false", but --ci-trust overrides that — so the scan correctly reported score 2/100 and 3 critical findings, exited 1, and never copied SARIF/HTML to the workspace (hence the artifact upload warnings).

Fix: Explicitly opt out in .github/workflows/action-validate.yml:

ci-trust: "false"
fail-on-critical: "false"

Raise fact_coverage to 80%, add fleet absolute-risk gates and auxiliary v2
gate parity, extend MCP/CLI trust surfaces, and apply ruff format to files
that were failing CI on PR #565.
The action defaults ci-trust to true, which overrides fail-on-critical false
and applies min-score 70 — intentional for real CI but breaks the validate
workflow that only checks report artifacts from the demo server.
When the semantic model is unavailable, the analyzer emits a coverage skip
finding that should not count as a credential detection in MCTS-T-1022 fixtures.
@hello-args hello-args merged commit 2aa032b into develop Jun 13, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant