From f5b11e30a4ccb86e0ee762a801930d8ded85c4d2 Mon Sep 17 00:00:00 2001 From: Till Faelligen <2353100+S7evinK@users.noreply.github.com> Date: Thu, 3 Nov 2022 08:20:51 +0100 Subject: [PATCH] Hopefully fix GHA sarif upload --- .github/workflows/docker.yml | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index b80afedfa..789f6c449 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -24,6 +24,7 @@ jobs: permissions: contents: read packages: write + security-events: write # To upload Trivy sarif files steps: - name: Checkout uses: actions/checkout@v3 @@ -75,7 +76,7 @@ jobs: output: "trivy-results.sarif" - name: Upload Trivy scan results to GitHub Security tab - uses: github/codeql-action/upload-sarif@v1 + uses: github/codeql-action/upload-sarif@v2 with: sarif_file: "trivy-results.sarif" @@ -103,6 +104,7 @@ jobs: permissions: contents: read packages: write + security-events: write # To upload Trivy sarif files steps: - name: Checkout uses: actions/checkout@v3 @@ -154,7 +156,7 @@ jobs: output: "trivy-results.sarif" - name: Upload Trivy scan results to GitHub Security tab - uses: github/codeql-action/upload-sarif@v1 + uses: github/codeql-action/upload-sarif@v2 with: sarif_file: "trivy-results.sarif"