From 2aec28f894a91e37bcc1d2cd2320fe4fb304e357 Mon Sep 17 00:00:00 2001 From: Aaron Goodfellow Date: Mon, 29 Sep 2025 15:56:45 -0400 Subject: [PATCH 1/2] docs(PI-5010): add section on minimum_score thresholds --- docs/advanced-configurations.md | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/docs/advanced-configurations.md b/docs/advanced-configurations.md index acd4348..d70a427 100644 --- a/docs/advanced-configurations.md +++ b/docs/advanced-configurations.md @@ -10,6 +10,7 @@ documented here. - [SBOM Generation](#sbom-generation) - [Custom Build Version Strings](custom-build-version-strings) - [Saving Action Minutes](#saving-action-minutes) +- [Minimum Score Thresholds](#minimum-score-thresholds) ## Action Configuration @@ -185,3 +186,34 @@ process: ``` This will delay the execution of the example `process` stage by the amount of minutes specified for the wait timer in the the "nowsecure-env" environment. + +## Minimum Score Thresholds + +The NowSecure Action also provides an optional `minimum_score` input which represents the score that your assessment needs to exceed. +If it does not, your pipeline will fail. This is valuable to ensure that your application's security scores do not decline as new versions are released. + +Note that this option is available on both the `convert-sarif` and `create-issues` actions + +```yml +- name: NowSecure download report + uses: nowsecure/nowsecure-action/convert-sarif@v3 + with: + report_id: ${{ needs.scan.outputs.report_id }} + platform_token: ${{ secrets.NS_TOKEN }} + group_id: ${{ vars.NS_GROUP }} + # TODO: Switch to whatever score threshold is right for your organization + minimum_score: 40 +``` + + +```yml +- name: NowSecure download report + uses: nowsecure/nowsecure-action/create-issues@v3 + with: + report_id: ${{ needs.scan.outputs.report_id }} + platform_token: ${{ secrets.NS_TOKEN }} + group_id: ${{ vars.NS_GROUP }} + config: "issues" + # TODO: Switch to whatever score threshold is right for your organization + minimum_score: 40 +``` From a710386912e8718144ceb2e81b51ebb06ee09706 Mon Sep 17 00:00:00 2001 From: Aaron Goodfellow Date: Wed, 1 Oct 2025 13:00:54 -0400 Subject: [PATCH 2/2] PR suggestion - add optionality note --- docs/advanced-configurations.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/docs/advanced-configurations.md b/docs/advanced-configurations.md index d70a427..023962c 100644 --- a/docs/advanced-configurations.md +++ b/docs/advanced-configurations.md @@ -192,7 +192,9 @@ This will delay the execution of the example `process` stage by the amount of mi The NowSecure Action also provides an optional `minimum_score` input which represents the score that your assessment needs to exceed. If it does not, your pipeline will fail. This is valuable to ensure that your application's security scores do not decline as new versions are released. -Note that this option is available on both the `convert-sarif` and `create-issues` actions +If the `minimum_score` input is not set, it will not be evaluated. + +Note that this input is available on both the `convert-sarif` and `create-issues` actions. ```yml - name: NowSecure download report