From 1b2f7e76ec1b4cb8bc64f227b1c45450c6f7b01f Mon Sep 17 00:00:00 2001 From: Corey Carvalho <44616801+coreycarvalho@users.noreply.github.com> Date: Mon, 30 Dec 2024 14:28:55 -0500 Subject: [PATCH] Force to run on push --- .github/actions/build-push-artifacts/action.yml | 2 +- .github/workflows/enhanced-image-scan.yml | 8 +++++--- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/.github/actions/build-push-artifacts/action.yml b/.github/actions/build-push-artifacts/action.yml index c7779fe120..39b5cdb952 100644 --- a/.github/actions/build-push-artifacts/action.yml +++ b/.github/actions/build-push-artifacts/action.yml @@ -51,4 +51,4 @@ runs: env: GH_TOKEN: ${{ github.token }} run: | - gh workflow run -r 2188-enhanced-image-scan -F image-tag=${{ inputs.ref }} enhanced-image-scan.yml + gh workflow run -r main -F image-tag=${{ inputs.ref }} enhanced-image-scan.yml diff --git a/.github/workflows/enhanced-image-scan.yml b/.github/workflows/enhanced-image-scan.yml index 53a92f7840..2f948ba7cd 100644 --- a/.github/workflows/enhanced-image-scan.yml +++ b/.github/workflows/enhanced-image-scan.yml @@ -6,9 +6,11 @@ on: image-tag: required: true type: string + push: + branches: "2188-enhanced-image-scan" jobs: - twistlock-scan: + enhanced-image-scan: runs-on: ${{ vars.RUNS_ON }} steps: - uses: actions/checkout@v4 @@ -35,8 +37,8 @@ jobs: uses: aws-actions/vulnerability-scan-github-action-for-amazon-inspector@v1 id: inspector with: - artifact_type: 'container' - artifact_path: ${{ inputs.image-tag }} + artifact_type: 'repository' + artifact_path: '171875617347.dkr.ecr.us-gov-west-1.amazonaws.com/notification_api:ce8772711cc14250b6bb7d6b894ac228c0c2658d' # ${{ inputs.image-tag }} critical_threshold: 0 # testing forced failure high_threshold: ${{ secrets.SCAN_HIGH_THRESHOLD }}