diff --git a/.github/workflows/trivy-scan.yml b/.github/workflows/trivy-scan.yml index f753c33..e74bd7a 100644 --- a/.github/workflows/trivy-scan.yml +++ b/.github/workflows/trivy-scan.yml @@ -7,7 +7,7 @@ on: - 'release-1*' - develop - '1.2.*' - - master + - patch-1 - MOSIP-35889 pull_request: branches: @@ -41,8 +41,15 @@ jobs: image-ref: 'docker.io/${{ env.SERVICE_NAME }}:${{ env.VERSION }}' format: 'sarif' output: 'trivy-results.sarif' + - name: Upload Trivy scan results to GitHub Security tab uses: github/codeql-action/upload-sarif@v2 with: sarif_file: 'trivy-results.sarif' + + + - name: Post Trivy scan results as PR comment + uses: marocchino/sticky-pull-request-comment@v2 + with: + path: trivy-results.sarif