Skip to content

Wrong severity mapping for native semgrep JSON parser #6289

Description

@Gby56

I think this is really wrong, WARNING level should be the same as the SARIF level https://docs.oasis-open.org/sarif/sarif/v2.0/csprd02/sarif-v2.0-csprd02.html#_Toc10127839
And this should be Medium in my opinion... or High, and ERROR should be Critical, this is all very weird to me
@damiencarol let me know what you think ? I haven't tried to ingest SARIF yet but I think it would reflect issues better

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions