Skip to content

validate-project action is too strict on security advisory URL #671

Description

@crenshaw-dev

The validator requires a GHSA report URL.

For projects like Argo with multiple subprojects, there's no single GHSA report link.

Example failure: https://github.com/argoproj/.project/actions/runs/34403020101/job/102639227931?pr=4

Project Validation Report
  ========================
  
  CHANGED: Argo (file:///home/runner/work/.project/.project/project.yaml)
    Previous Hash: 
    Current Hash:  5f5384962bb42fa4ef84760485890a1fb278a0bc0ce7fe365f65c3558e4a479d
  INVALID: Argo (file:///home/runner/work/.project/.project/project.yaml)
    - security.contact.advisory_url must be a valid GitHub Security Advisory URL ([https://github.com/{org}/{repo}/security/advisories/new](https://github.com/%7Borg%7D/%7Brepo%7D/security/advisories/new)), got: https://github.com/argoproj/argoproj/blob/main/SECURITY.md#reporting-vulnerabilities
  
  Summary: 1 projects validated, 1 changed, 1 with errors
  Error: Process completed with exit code 1.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

area/dot-projectutilities/dot-project scaffolding and bootstrap toolingneeds-groupIndicates an issue or PR that has not been assigned a group (toc or tag/foo label applied)needs-kindIndicates an issue or PR that is missing an issue type or kind (a kind/foo label)needs-priorityIndicates an issue or PR missing a priority labelneeds-statusIndicates an issue or PR missing a status labelneeds-triageIndicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions