Skip to content

v1.1.0 - Known-safe finding downgrades

Latest

Choose a tag to compare

@Jarnon404 Jarnon404 released this 10 Jul 04:24
· 1 commit to main since this release
60d128d

Release v1.1.0.

Adds:

  • Known-safe downgrade logic for sanitized documentation examples
  • Downgrades selected false positives from WARN to INFO
  • Known-safe findings documentation
  • Safer handling for example.com, admin.user@example.com, contoso.local and DC01.contoso.local
  • GitHub Actions references such as GITHUB_TOKEN, secrets.GITHUB_TOKEN and id-token are treated as known-safe in the audit tool repository context

This release reduces false positives while keeping conservative public-safe checks enabled.