[mimosa] Git gate blocks on pre-existing findings; policy exclusions not honored — request staged-scope gate / exclusions / findings baseline
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 45/100
Direzione di ricerca
Start with the pre-commit git gate, the MCP normal-depth scan, and .mimosa/security-policy.json; inspect how threatModel.exclusions are processed. Review findings-import.json, verdictEffect, and the security-scan compare normalized identities before choosing among staged-scope scanning, honored exclusions, or a findings baseline. Done means the selected behavior is documented and the gate no longer blocks on unaffected or explicitly excluded pre-existing findings.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Environment
- mimosa 1.0.3 from the
zcode-plugins-officialmarketplace, ZCode on macOS (Apple Silicon)
Use case
Our repository is an evidence/audit archive. It intentionally retains: quarantined credential material (kept for an Owner rotation decision), historical controller snapshots, and test fixtures containing deliberately vulnerable patterns.
Observed (v1.0.3)
- The pre-commit git gate scans the whole working tree on every commit and hard-blocks on pre-existing findings (~1.1k), including files untouched by the commit. For archive-style repos this means every commit is blocked regardless of its content.
.mimosa/security-policy.json→threatModel.exclusionsdoes not appear to be honored: after adding directory-level globs, results were byte-identical for the git gate, and a normal-depth MCP scan still attributes ~90% of findings (817/904) to the excluded directories.findings-import.json/verdictEffectseem to be MCP reporting semantics only (contract doc: "verdictEffectremainsnoneuntil the product adopts a separate reviewed policy"); there is no documented mechanism to feed a findings baseline into the gate.
Requests (any one would resolve it)
- Git gate scope option — scan staged/changed files only (classic pre-commit semantics); keep the full-tree scan for the explicit deep-audit path.
- Honor
threatModel.exclusionsin both the git gate and normal-depth scan decisions. - Findings baseline — let a sealed scan be imported as "acknowledged/baselined" so the gate only reports new finding identities; the
security-scan comparenormalized identities look like a natural fit.
Happy to test a pre-release against our repo.
- Lingua principale
- Python
- Stelle
- 39
- Fork
- 20
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di zai-org/zcode-plugins
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
zai-org/zcode-plugins#14 ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 38/100
zai-org/zcode-plugins#44 ·
-
[mimosa 1.0.3] 深扫 worker 未构建:security-scan-worker.mimosa 解密为空模块,security_scan 恒返回 inconclusive Aperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 40/100
zai-org/zcode-plugins#41 ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 40/100
zai-org/zcode-plugins#37 ·
-
今天你上传代码了吗 Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 20/100
zai-org/zcode-plugins#36 · 1 reazione ·
Tutte le issue di zai-org/zcode-plugins
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
browser-use/browser-use#5905 ·
-
type: enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
ynput/ayon-python-api#363 ·
-
bug needs triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
modelscope/FunASR#3728 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
open-compass/opencompass#2655 ·