Skip to content

CI: vuln-scanner and SAST fail — ih-github command not found #22

@akuzminsky

Description

@akuzminsky

Problem

The sast-check and vulnerability-check jobs in vuln-scanner-pr.yml fail because
ih-github is not available on the runner:

/home/runner/work/_temp/0d8af7d2-8f2d-4767-ab7d-29490e7b3b23.sh: line 3: ih-github: command not found

The workflow installs semgrep but doesn't install infrahouse-toolkit which provides ih-github.

Seen in: https://github.com/infrahouse/aws-service-infrahouse-app/actions/runs/26368785686/job/77617081592

Context

This workflow is managed by github-control and injected into service repos. The aws_service template
repos use GitHub-hosted runners which don't have ih-github pre-installed.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions