CVE auto-fail list
Specify a list of CVE identifiers that will always fail the build when detected, regardless of other threshold settings.
Supported Formats:
- Comma-separated: CVE-2023-9999, CVE-2024-0001
- One per line:
CVE-2023-9999
CVE-2024-0001
- Mixed format: CVE-2023-9999, CVE-2024-0001
CVE-2024-0002
Behavior:
- Runs independently of vulnerability threshold settings
- Takes precedence over the CVE suppression list
- Immediately fails the build when any auto-fail CVE is detected
Note: CVE IDs must follow the format CVE-YYYY-NNNN (e.g., CVE-2023-1234)