Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Add OSV scanner#7768

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Draft
mhucka wants to merge5 commits intoquantumlib:main
base:main
Choose a base branch
Loading
frommhucka:mh-update-scanners
Draft

Conversation

@mhucka
Copy link
Contributor

@mhuckamhucka commentedNov 23, 2025
edited
Loading

This is almost identical to the latest version of this scanner used in the qsim repository.

This is almost identical to the latest version used in the qsimrepository. It has a minor improvement in using an `ubuntu-slim` runnerfor the summary-writing job and also respecting the `runner.debug`variable.
This is almost identical to the latest version used in the qsimrepository. It has a minor improvement in respecting the `runner.debug`variable.
@mhuckamhucka requested review froma team andvtomole ascode ownersNovember 23, 2025 00:31
@github-actionsgithub-actionsbot added the size: L250< lines changed <1000 labelNov 23, 2025
@github-advanced-security

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear onthis overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check outthe documentation.

@codecov
Copy link

codecovbot commentedNov 23, 2025
edited
Loading

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 99.57%. Comparing base (c6c0eff) to head (9a91b4a).

Additional details and impacted files
@@            Coverage Diff             @@##             main    #7768      +/-   ##==========================================- Coverage   99.57%   99.57%   -0.01%==========================================  Files        1102     1102                Lines       98425    98425              ==========================================- Hits        98006    98005       -1- Misses        419      420       +1

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report?Share it here.

🚀 New features to boost your workflow:
  • ❄️Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Copy link
Collaborator

@pavoljuhaspavoljuhas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

Let us run these as scheduled scans to save on resources and avoid user confusion.

Also please move the introduction of osv-scan to its own PR.

@@ -0,0 +1,145 @@
# Copyright 2025 Google LLC
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

Can you please move this to a separate PR?

Also, let us try to keep this as simple and as close as possible to the example workflows athttps://github.com/google/osv-scanner. Running this on schedule should be sufficient; again, we do not need to create noise in CI-checks for our contributors. (we have no large scale continuous deployment of Cirq so it is not that critical to catch vulnerabilities on the spot. Also the only kind of PRs that can introduce them are changes Python dependencies or GHA workflows)

Copy link
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

I moved the Scorecard changes to another PR (#7776)

The changes are being done in another PR:quantumlib#7776
@github-actionsgithub-actionsbot added size: M50< lines changed <250 and removed size: L250< lines changed <1000 labelsNov 28, 2025
@mhuckamhucka changed the titleUpdate Scorecard scanner and add OSV scannerAdd OSV scannerNov 28, 2025
@mhuckamhucka marked this pull request as draftNovember 28, 2025 05:18
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@pavoljuhaspavoljuhaspavoljuhas requested changes

@vtomolevtomoleAwaiting requested review from vtomolevtomole is a code owner

@95-martin-orion95-martin-orionAwaiting requested review from 95-martin-orion95-martin-orion is a code owner automatically assigned from quantumlib/cirq-maintainers

Requested changes must be addressed to merge this pull request.

Assignees

No one assigned

Labels

area/cisize: M50< lines changed <250

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

2 participants

@mhucka@pavoljuhas

[8]ページ先頭

©2009-2025 Movatter.jp