From 57b9fcb7d99c59e74bc5606b19f5164b48fd6971 Mon Sep 17 00:00:00 2001 From: naveensrinivasan <172697+naveensrinivasan@users.noreply.github.com> Date: Sat, 30 Mar 2024 12:02:58 -0500 Subject: [PATCH] included sarif publish Signed-off-by: naveensrinivasan <172697+naveensrinivasan@users.noreply.github.com> --- .github/workflows/scan-vulnerability.yaml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/scan-vulnerability.yaml b/.github/workflows/scan-vulnerability.yaml index 88108788..a8751a26 100644 --- a/.github/workflows/scan-vulnerability.yaml +++ b/.github/workflows/scan-vulnerability.yaml @@ -32,3 +32,8 @@ jobs: - name: Scan the repository for vulnerabilities run: | uds run vuln-check:grype-scan-sbom + + - name: Upload SARIF files + uses: github/codeql-action/upload-sarif@v1 + with: + sarif_file: 'sarif/*.sarif'