Skip to content

feat(scan): run deterministic scanners and honor ignore.rules / cora-ignore in cora scan #595

Description

@ajianaz

Problem

cora scan is LLM-only: it does not run the secrets/security scanners and does not apply ignore.rules or the inline cora-ignore: marker added in #554/#593 (those only apply in cora review). An LLM 502 therefore yields "No issues found" even for an obvious hardcoded password.

Direction

Run the deterministic stage on scanned files, merge with LLM findings, and apply ignore.rules + inline_suppress::apply (reading markers from file contents instead of diff lines).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions