Commit e5a6398
docs(security): clarify Scorecard findings surface as code scanning alerts
CodeRabbit flagged that Scorecard appeared in the scanning-tools list
but wasn't covered explicitly by any dismissal-flow section. In our
setup, Scorecard publishes SARIF that surfaces as code scanning alerts
in GitHub's UI (that's the channel by which alert #565 — Scorecard
DangerousWorkflowID — was dismissed via the two-person flow). Adds an
intro sentence making this coverage explicit so an auditor reading the
doc doesn't have to infer it.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent 6ecddef commit e5a6398
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
42 | 42 | | |
43 | 43 | | |
44 | 44 | | |
45 | | - | |
| 45 | + | |
46 | 46 | | |
47 | 47 | | |
48 | 48 | | |
| |||
0 commit comments