Skip to content

Conversation

@mergify
Copy link
Contributor

@mergify mergify bot commented Aug 4, 2025

This commit updates the grype action to log what components it is scanning (including any that are critical which will cause the action to fail). Previously the default sarif file was generated and nothing was logged. Without this commit it is impossible to tell from a failed action what is causing the failure.

See https://github.com/anchore/scan-action?tab=readme-ov-file#action-inputs which indicates this option should do what we want.


This is an automatic backport of pull request #17905 done by Mergify.

This commit updates the grype action to log what components it is scanning
(including any that are critical which will cause the action to fail).
Previously the default sarif file was generated and nothing was logged. Without
this commit it is impossible to tell from a failed action *what* is causing the
failure.

(cherry picked from commit 6b8d090)
@donoghuc donoghuc merged commit 749cae7 into 8.19 Aug 4, 2025
5 checks passed
@donoghuc donoghuc deleted the mergify/bp/8.19/pr-17905 branch August 4, 2025 18:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants