[mimosa] Git gate blocks on pre-existing findings; policy exclusions not honored — request staged-scope gate / exclusions / findings baseline
メンテナーはふだん 3 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 45/100
調査の方向性
Start with the pre-commit git gate, the MCP normal-depth scan, and .mimosa/security-policy.json; inspect how threatModel.exclusions are processed. Review findings-import.json, verdictEffect, and the security-scan compare normalized identities before choosing among staged-scope scanning, honored exclusions, or a findings baseline. Done means the selected behavior is documented and the gate no longer blocks on unaffected or explicitly excluded pre-existing findings.
索引モデルが issue の本文から書いたものです。
説明
Environment
- mimosa 1.0.3 from the
zcode-plugins-officialmarketplace, ZCode on macOS (Apple Silicon)
Use case
Our repository is an evidence/audit archive. It intentionally retains: quarantined credential material (kept for an Owner rotation decision), historical controller snapshots, and test fixtures containing deliberately vulnerable patterns.
Observed (v1.0.3)
- The pre-commit git gate scans the whole working tree on every commit and hard-blocks on pre-existing findings (~1.1k), including files untouched by the commit. For archive-style repos this means every commit is blocked regardless of its content.
.mimosa/security-policy.json→threatModel.exclusionsdoes not appear to be honored: after adding directory-level globs, results were byte-identical for the git gate, and a normal-depth MCP scan still attributes ~90% of findings (817/904) to the excluded directories.findings-import.json/verdictEffectseem to be MCP reporting semantics only (contract doc: "verdictEffectremainsnoneuntil the product adopts a separate reviewed policy"); there is no documented mechanism to feed a findings baseline into the gate.
Requests (any one would resolve it)
- Git gate scope option — scan staged/changed files only (classic pre-commit semantics); keep the full-tree scan for the explicit deep-audit path.
- Honor
threatModel.exclusionsin both the git gate and normal-depth scan decisions. - Findings baseline — let a sealed scan be imported as "acknowledged/baselined" so the gate only reports new finding identities; the
security-scan comparenormalized identities look like a natural fit.
Happy to test a pre-release against our repo.
- 主要言語
- Python
- スター
- 39
- フォーク
- 20
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
zai-org/zcode-plugins のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
zai-org/zcode-plugins#14 ·
メンテナーはふだん 3 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 38/100
zai-org/zcode-plugins#44 ·
メンテナーはふだん 3 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 40/100
zai-org/zcode-plugins#41 ·
メンテナーはふだん 3 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 40/100
zai-org/zcode-plugins#37 ·
メンテナーはふだん 3 日以内に返信
-
今天你上传代码了吗オープン
難易度 1/5 1時間未満 初心者へのやさしさ 20/100
zai-org/zcode-plugins#36 · リアクション 1 件 ·
メンテナーはふだん 3 日以内に返信
zai-org/zcode-plugins の issue をすべて見る
似ている issue
-
documentation
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
kristofdegrave/homeassistant-smart-charging#1413 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
nasa/earthdata-varinfo#113 ·
-
curriculum documentation quality
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
githubnext/gh-aw-workshop#3849 ·
メンテナーはふだん 2 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 90/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
メンテナーはふだん 1 日以内に返信