Try to add security-events: write to trivy scan (#2187)

Signed-off-by: Avgustin Marinov <Avgustin.Marinov@bosch.com>
This commit is contained in:
Avgustin Marinov
2025-01-09 14:52:39 +02:00
committed by GitHub
parent dc33056ccd
commit 07153ee15d

View File

@@ -6,14 +6,16 @@ on:
- cron: '0 4 * * *'
# enable running the workflow manually
workflow_dispatch:
pull_request:
paths:
- '.github/trivy-scan.yml'
jobs:
scan:
runs-on: ubuntu-latest
permissions:
contents: read
packages: read
security-events: write
steps:
- name: Checkout code
uses: actions/checkout@v4
@@ -59,5 +61,4 @@ jobs:
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: 'scans/eclipse-hawkbit/hawkbit/hawkbit-update-server:latest.sarif'
category: "Container Images"
debug: true
category: "Container Images"