Skip to content

Use main ref for official SAST scan template - #158

Merged
tonzhan2 merged 1 commit into
mainfrom
fix/vuln-84894-sast-template-ref
Jul 27, 2026
Merged

tonzhan2 merged 1 commit into
mainfrom
fix/vuln-84894-sast-template-ref

Conversation

@tonzhan2

Copy link
Copy Markdown
Contributor

Summary

  • Changed the SAST include in .gitlab-ci.yml from ref: master to ref: main so it tracks the current official ProdSec template (ci-cd/templates → /prodsec/.sast-scan.yml).
  • Resolves VULN ticket, detect-unofficial-sast-template finding was triggered by the outdated master ref (the project/file were already correct).
  • sast-scanner job unchanged (still extends: .sast_scan, alert_mode: "policy").

Notes

  • The oss-scan include is still on ref: master; left as-is since it's out of scope for this ticket.

@tonzhan2
tonzhan2 requested review from a team as code owners July 27, 2026 20:52
@tonzhan2
tonzhan2 merged commit b1f9c18 into main Jul 27, 2026
2 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Jul 27, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants