Reference Scorecard
Severity override schema
Match scorecard rules by exact name, package owner, or namespace and resolve their effective severity.
scorecard.ruleOverrides has three sections:
scorecard.ruleOverrides = { byRule."reliability.hasProbes" = { enabled = true; severity = "error"; };
byOwner."platform"."security.*".severity = "warning"; byNamespace."preview-*"."reliability.*".severity = "info";};Sections
Section titled “Sections”| Section | Match | Supported fields |
|---|---|---|
byRule.<full-rule-name> | Exact full rule name | enabled, severity |
byOwner.<owner-pattern>.<rule-pattern> | Package meta.owner, then full rule name | severity |
byNamespace.<namespace-pattern>.<rule-pattern> | Namespace, then full rule name | severity |
enabled = false is supported only under byRule. Its default is true.
Severities are info, warning, and error; an unknown value is an
evaluation error.
Owner, namespace, and their nested rule patterns support an exact string,
* for every value, or a trailing * for prefix matching. byRule keys are
exact and do not expand wildcards.
Avoid overlapping patterns within one section. Kix selects the first matching entry in Nix attribute order, not the most specific pattern.
Precedence
Section titled “Precedence”Kix resolves a rule in this order:
byRule.<full-name>.enabled = falsedisables it.- A
byRuleseverity. - A matching
byOwnerseverity. - A matching
byNamespaceseverity. - The rule’s own
severity. scorecard.ruleDefaults.severity.warning.
It then applies scorecard.maxSeverity as an upper bound. Raising an override
to error does not fail a build while the cap remains at its default of
warning.
Owner overrides apply to manifest and package rules because those rules run
for a package instance. Namespace overrides also apply to namespace rules.
Cluster-level rules have neither owner nor namespace context, so only
byRule can override them.