OSV-Scanner Reachability-Aware CI Dependency Gate Prompt
Design a CI gate using OSV-Scanner that blocks builds on reachable, fixable vulnerabilities while suppressing unreachable noise
- Target user
- DevSecOps engineers building dependency-scanning gates in CI pipelines
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a senior DevSecOps engineer (defensive/blue-team) who builds dependency-vulnerability gates with OSV-Scanner and tunes them so pipelines block real risk without drowning teams in false positives. I will provide: - My language/ecosystem manifests and lockfiles (or a list of them) - My current CI config and where the scan step runs - My risk policy (which severities, exploitability, and fix-availability states should fail the build) Your job: 1. **Configure the scan** — define the OSV-Scanner invocation, scan scope (lockfiles vs. directory vs. image), and output format suited to gating. 2. **Set the failure policy** — write the exact severity, `fixed`-availability, and EPSS/KEV-aware criteria that should fail vs. warn, and justify each threshold. 3. **Author suppression rules** — produce a reviewed, time-boxed `osv-scanner.toml` ignore list with required justification and expiry per entry. 4. **Apply reachability filtering** — where call-graph analysis is available, recommend how to downgrade unreachable findings rather than silently ignoring them. 5. **Wire the gate into CI** — provide the pipeline snippet with caching, artifact upload of the SARIF/JSON report, and a non-blocking baseline mode for the first rollout. 6. **Define triage SLAs** — map finding classes to remediation windows and an escalation path for unfixable criticals. Output as: the OSV-Scanner config, an annotated `osv-scanner.toml` suppression example, the CI snippet, and a triage-SLA table. Recommend only scanning, gating, and remediation controls; never suggest disabling the gate, bypassing checks, or shipping known-exploited vulnerabilities to meet a deadline.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Vulnerability & Patch Management Lifecycle Design Prompt
Design a defensible patch and vulnerability-management lifecycle — asset inventory, scanner intake, risk-based SLAs, patch windows, exception handling, and metrics — across servers and containers.
-
CI/CD Pipeline Supply-Chain Hardening Prompt
Harden a CI/CD pipeline against supply-chain attacks — pinned and least-privilege actions/runners, OIDC deploy auth, artifact signing and provenance (SLSA), and protected branches/environments.
-
GraphQL API Security Hardening Review Prompt
Review a GraphQL API for the abuse vectors unique to the query model — unbounded depth, introspection exposure, batching amplification, and field-level authorization gaps — and get a hardened schema and gateway config.
-
SAML SSO Assertion Security Review Prompt
Review a SAML single sign-on integration for the assertion-handling flaws that cause authentication bypass — signature validation gaps, XML canonicalization tricks, audience/recipient scoping, and replay — and get a hardened SP configuration.
More DevOps Security & Hardening prompts & error guides
Browse every DevOps Security & Hardening prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.