From fe3402f625ece904a7a1dd3fa9403b01178e0681 Mon Sep 17 00:00:00 2001 From: Ramon <115667262+RamonDevPrivate@users.noreply.github.com> Date: Wed, 30 Sep 2026 23:42:39 +0200 Subject: [PATCH] chore: changed report behavior for ci checks Changed exit code for Trivy scanner from '1' to '0' and updated conditions for uploading reports to the security tab. --- .github/workflows/ci.yml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 30f388e..ae96f7a 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -272,10 +272,10 @@ jobs: format: sarif output: trivy-results.sarif severity: 'CRITICAL,HIGH,MEDIUM' - exit-code: '1' + exit-code: '0' ignore-unfixed: true - name: Upload trivy report to security tab - if: always() && github.event.repository.visibility == 'public' && github.ref == 'refs/heads/main' + if: always() && github.event.repository.visibility == 'public' uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 with: sarif_file: trivy-results.sarif @@ -288,7 +288,7 @@ jobs: zricethezav/gitleaks:v8.30.0 \ git --redact --report-format sarif --report-path gitleaks.sarif . - name: Upload gitleaks report to security tab - if: always() && github.event.repository.visibility == 'public' && github.ref == 'refs/heads/main' + if: always() && github.event.repository.visibility == 'public' uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 with: sarif_file: gitleaks.sarif @@ -400,7 +400,7 @@ jobs: echo "No semgrep.sarif found" fi - name: Upload Semgrep results to Github Security tab - if: always() && github.event.repository.visibility == 'public' && github.ref == 'refs/heads/main' + if: always() && github.event.repository.visibility == 'public' uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 with: sarif_file: semgrep.sarif