[mimosa] Git gate blocks on pre-existing findings; policy exclusions not honored — request staged-scope gate / exclusions / findings baseline
Los mantenedores suelen responder en 3 días
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 45/100
Línea de trabajo
Start with the pre-commit git gate, the MCP normal-depth scan, and .mimosa/security-policy.json; inspect how threatModel.exclusions are processed. Review findings-import.json, verdictEffect, and the security-scan compare normalized identities before choosing among staged-scope scanning, honored exclusions, or a findings baseline. Done means the selected behavior is documented and the gate no longer blocks on unaffected or explicitly excluded pre-existing findings.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Environment
- mimosa 1.0.3 from the
zcode-plugins-officialmarketplace, ZCode on macOS (Apple Silicon)
Use case
Our repository is an evidence/audit archive. It intentionally retains: quarantined credential material (kept for an Owner rotation decision), historical controller snapshots, and test fixtures containing deliberately vulnerable patterns.
Observed (v1.0.3)
- The pre-commit git gate scans the whole working tree on every commit and hard-blocks on pre-existing findings (~1.1k), including files untouched by the commit. For archive-style repos this means every commit is blocked regardless of its content.
.mimosa/security-policy.json→threatModel.exclusionsdoes not appear to be honored: after adding directory-level globs, results were byte-identical for the git gate, and a normal-depth MCP scan still attributes ~90% of findings (817/904) to the excluded directories.findings-import.json/verdictEffectseem to be MCP reporting semantics only (contract doc: "verdictEffectremainsnoneuntil the product adopts a separate reviewed policy"); there is no documented mechanism to feed a findings baseline into the gate.
Requests (any one would resolve it)
- Git gate scope option — scan staged/changed files only (classic pre-commit semantics); keep the full-tree scan for the explicit deep-audit path.
- Honor
threatModel.exclusionsin both the git gate and normal-depth scan decisions. - Findings baseline — let a sealed scan be imported as "acknowledged/baselined" so the gate only reports new finding identities; the
security-scan comparenormalized identities look like a natural fit.
Happy to test a pre-release against our repo.
- Lenguaje dominante
- Python
- Estrellas
- 39
- Forks
- 20
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de zai-org/zcode-plugins
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
zai-org/zcode-plugins#14 ·
Los mantenedores suelen responder en 3 días
-
Dificultad 4/5 3-5 días Aptitud para principiantes 38/100
zai-org/zcode-plugins#44 ·
Los mantenedores suelen responder en 3 días
-
[mimosa 1.0.3] 深扫 worker 未构建:security-scan-worker.mimosa 解密为空模块,security_scan 恒返回 inconclusiveAbierto
Dificultad 4/5 3-5 días Aptitud para principiantes 40/100
zai-org/zcode-plugins#41 ·
Los mantenedores suelen responder en 3 días
-
Dificultad 4/5 3-5 días Aptitud para principiantes 40/100
zai-org/zcode-plugins#37 ·
Los mantenedores suelen responder en 3 días
-
今天你上传代码了吗Abierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 20/100
zai-org/zcode-plugins#36 · 1 reacción ·
Los mantenedores suelen responder en 3 días
Todos los issues de zai-org/zcode-plugins
Issues similares
-
documentation
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
kristofdegrave/homeassistant-smart-charging#1413 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
nasa/earthdata-varinfo#113 ·
-
curriculum documentation quality
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
githubnext/gh-aw-workshop#3849 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 90/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Los mantenedores suelen responder en 1 día