Skip to content

Bump github/codeql-action from 2 to 3 #53

Bump github/codeql-action from 2 to 3

Bump github/codeql-action from 2 to 3 #53

Workflow file for this run

on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
container-scan-to-sarif_job:
runs-on: ubuntu-latest
name: Upload Container Scan Report to GitHub Code Scanning
permissions:
security-events: write
steps:
- uses: actions/checkout@v4
- name: Scan sample image with Azure Container Scan
id: container-image-scan
continue-on-error: true
uses: Azure/container-scan@v0.1
with:
image-name: "busybox:1.35.0"
- name: Convert Container Scan Output to SARIF
id: container-scan-to-sarif
if: ${{ always() }}
uses: ./
with:
input-file: ${{ steps.container-image-scan.outputs.scan-report-path }}
- name: Upload SARIF reports to GitHub Security tab
uses: github/codeql-action/upload-sarif@v3
if: ${{ always() }}
with:
sarif_file: ${{ steps.container-scan-to-sarif.outputs.sarif-report-path }}