You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
After calling checkov-action in a workflow, the Severity filter in Code scanning in Github shows the regular checkov severities (low, medium, high and critical). Since checkov-action always reports error, these make no sense to even be in the filter list.
The text was updated successfully, but these errors were encountered:
Severity levels are perfectly useful, and it's quite annoying that all findings are reported as Errors.
Why does Chekov not reproduce the severity defined for each rule in SARIF reports?
After calling checkov-action in a workflow, the Severity filter in Code scanning in Github shows the regular checkov severities (low, medium, high and critical). Since checkov-action always reports
error
, these make no sense to even be in the filter list.The text was updated successfully, but these errors were encountered: