Static-analyzer integration increments so inspect plugs into CI and code-scanning.
Items
- SARIF output — emit findings as SARIF so they drop into code-scanning / CI annotations.
- Suppression / allowlist —
# aegis: ignore inline + a config allowlist for accepted sinks.
- CI exit codes — non-zero exit on new critical flows, for gating.
- Signed, no-egress attestation + SBOM — for the local/keyless run, to back the "local & keyless" claim.
These can ship independently; grouped here as the CI/output theme.
Source: docs/issues/inspect-followups.md (Static analyzer — next increments)
Static-analyzer integration increments so
inspectplugs into CI and code-scanning.Items
# aegis: ignoreinline + a config allowlist for accepted sinks.These can ship independently; grouped here as the CI/output theme.
Source:
docs/issues/inspect-followups.md(Static analyzer — next increments)