Closed pradeepp88 closed 2 months ago
@swcurran / @WadeBarnes - can you please check the Snyk account to see if the scans are running there? The Github action shows the last container ran 5 months ago.
It does appear to be running:
@WadeBarnes thanks for checking. So it is an integration issue with Github to view the results.
Is there a public link to view the Snyk scanning results directly from there?
@pradeepp88, Submitted a PR here that should fix the Sync Container scanning issues; https://github.com/hyperledger/aries-cloudagent-python/pull/2951
Thanks @WadeBarnes but still the sarif file is having some config errors and the workflow fails
@WadeBarnes submitted a PR #2961 to fix this issue.
This fix was merged so I believe this issue can be closed.
https://github.com/hyperledger/aries-cloudagent-python/blob/f9d9baded73e49bb796ded1ed9f327dd98ce1c14/.github/workflows/snyk.yml#L1C1-L7C15
Opening this issue to review the Snyk container scan not being run on every PR as configured.