[codex] sbom-diff-and-risk v0.3.0 - #9
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6fb90f5cab
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if not isinstance(value, (int, float)): | ||
| raise PolicyError(f"Invalid policy schema in {context}: expected a number between 0 and 10.") | ||
| normalized = float(value) | ||
| if normalized < 0 or normalized > 10: | ||
| raise PolicyError(f"Invalid policy schema in {context}: expected a number between 0 and 10.") |
There was a problem hiding this comment.
Reject boolean and NaN scorecard thresholds
minimum_scorecard_score currently accepts any int/float, so YAML values like true (treated as 1.0) and .nan pass validation; .nan in particular bypasses the range check and then makes every scored component look below threshold because comparisons against NaN are always false. This can silently turn a misconfigured policy into widespread false violations, so parsing should explicitly reject booleans and non-finite floats.
Useful? React with 👍 / 👎.
|
Opened follow-up PR #10 to address the minimum_scorecard_score review issue. It rejects YAML booleans and non-finite values (.nan, .inf, -.inf) at parse time and adds regression tests for those cases. |
Summary
sbom-diff-and-riskfor thev0.3.0release0.3.0and make SARIF golden tests path-stable across environmentsValidation
pytest