Skip to content

Exclude dependencies from wolfTrust Coverity scans - #62

Open
aidangarske wants to merge 4 commits into
wolfSSL:mainfrom
aidangarske:fix/coverity-scope
Open

aidangarske wants to merge 4 commits into
wolfSSL:mainfrom
aidangarske:fix/coverity-scope

Conversation

@aidangarske

Copy link
Copy Markdown
Member
  • Prevent submodule findings from entering wolfTrust's Coverity results.
  • Remove dependency and external source units before upload.
  • Reject submodules outside the configured dependency exclusion.
  • Reject empty, malformed, or improperly filtered captures.
  • Keep weekly scans and require HTTP 201 for upload acceptance.
  • Validate filtering with the real Coverity SDK and negative fixtures.

Copilot AI balanced review requested due to automatic review settings October 2, 2026 00:01

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Security-analysis coverage depends partly on external Coverity configuration and SDK behavior that requires final human verification.

Review effort: Balanced
Findings: None

What changed in this PR

Restricts Coverity uploads to wolfTrust-owned translation units and changes scans to weekly or manual execution.

Changes:

  • Adds capture filtering and validation.
  • Separates capture, filtering, and HTTP-validated upload.
  • Documents dependency exclusions and scan scheduling.
File Description
tools/​ci-coverity-filter.py Removes dependency and external translation units.
.github/​workflows/​coverity.yml Filters captures before weekly/manual uploads.
.github/​workflows/​README.md Documents Coverity scope and configuration.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants