Closed
Description
It is surprising to enable the action and not see it fail when there are vulnerabilities at or above medium severity.
Most actions out there and linters in general have a failure enabled by default, which can then be turned off.
@zhill is there a historical reason why we couldn't change this default?