ods-jenkins-shared-library
ods-jenkins-shared-library copied to clipboard
Wrong Documentation around Snyk
Is your feature request related to a problem? Please describe.
--severity-threshold
flag not doing what it's promising it should do.
On the ODS docs, it says
Severity threshold for failing. If any found vulnerability has a severity equal or
higher to the threshold, the snyk test will return with a failure status...
whereas on Snyk documentation we have:
--severity-threshold: Only report vulnerabilities of provided level or higher.
ODS Version: 3.x and on
Hi @sino92! Could you elaborate a bit more what the issue is? For me they read the same, just with the difference that we let the pipeline in which the scan happens fail additionally based on the reported vulns.