[mimosa] Git gate blocks on pre-existing findings; policy exclusions not honored — request staged-scope gate / exclusions / findings baseline
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 45/100
Hướng nghiên cứu
Start with the pre-commit git gate, the MCP normal-depth scan, and .mimosa/security-policy.json; inspect how threatModel.exclusions are processed. Review findings-import.json, verdictEffect, and the security-scan compare normalized identities before choosing among staged-scope scanning, honored exclusions, or a findings baseline. Done means the selected behavior is documented and the gate no longer blocks on unaffected or explicitly excluded pre-existing findings.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Environment
- mimosa 1.0.3 from the
zcode-plugins-officialmarketplace, ZCode on macOS (Apple Silicon)
Use case
Our repository is an evidence/audit archive. It intentionally retains: quarantined credential material (kept for an Owner rotation decision), historical controller snapshots, and test fixtures containing deliberately vulnerable patterns.
Observed (v1.0.3)
- The pre-commit git gate scans the whole working tree on every commit and hard-blocks on pre-existing findings (~1.1k), including files untouched by the commit. For archive-style repos this means every commit is blocked regardless of its content.
.mimosa/security-policy.json→threatModel.exclusionsdoes not appear to be honored: after adding directory-level globs, results were byte-identical for the git gate, and a normal-depth MCP scan still attributes ~90% of findings (817/904) to the excluded directories.findings-import.json/verdictEffectseem to be MCP reporting semantics only (contract doc: "verdictEffectremainsnoneuntil the product adopts a separate reviewed policy"); there is no documented mechanism to feed a findings baseline into the gate.
Requests (any one would resolve it)
- Git gate scope option — scan staged/changed files only (classic pre-commit semantics); keep the full-tree scan for the explicit deep-audit path.
- Honor
threatModel.exclusionsin both the git gate and normal-depth scan decisions. - Findings baseline — let a sealed scan be imported as "acknowledged/baselined" so the gate only reports new finding identities; the
security-scan comparenormalized identities look like a natural fit.
Happy to test a pre-release against our repo.
- Ngôn ngữ chính
- Python
- Star
- 39
- Fork
- 20
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của zai-org/zcode-plugins
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
zai-org/zcode-plugins#14 ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 38/100
zai-org/zcode-plugins#44 ·
-
[mimosa 1.0.3] 深扫 worker 未构建:security-scan-worker.mimosa 解密为空模块,security_scan 恒返回 inconclusive Đang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 40/100
zai-org/zcode-plugins#41 ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 40/100
zai-org/zcode-plugins#37 ·
-
今天你上传代码了吗 Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 20/100
zai-org/zcode-plugins#36 · 1 reaction ·
Tất cả issue của zai-org/zcode-plugins
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
browser-use/browser-use#5905 ·
-
type: enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
ynput/ayon-python-api#363 ·
-
bug needs triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
modelscope/FunASR#3728 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
open-compass/opencompass#2655 ·