sett-and-hive / sarif-to-comment-action

A GitHub action for @security-alert/sarif-to-comment
MIT License
7 stars 4 forks source link

bug: SonarCloud Security HotSpot: should add --ignore-scripts in Dockerfile #309

Closed tomwillis608 closed 1 month ago

tomwillis608 commented 1 month ago

Version

main

Current Behavior

RUN npm install

Expected Behavior

RUN npm install --ignore-scripts

Steps to Reproduce

build the docker, e.g. bash test/trivy.sh

Additional Information

https://sonarcloud.io/project/security_hotspots?id=tomwillis608_sarif-to-comment-action&hotspots=AYs715205RI1CJIe2qfd