Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Push Mend scan results for main branch only #651

Open
leochr opened this issue May 22, 2024 · 0 comments
Open

Push Mend scan results for main branch only #651

leochr opened this issue May 22, 2024 · 0 comments

Comments

@leochr
Copy link
Member

leochr commented May 22, 2024

The Mend scan results from personal builds are being pushed to the central Mend dashboard we monitor. Only the results from the main branch should be pushed to the dashboard.

The compliance check stage runs the Mend scanner, but since the Operator code is not 'built' at that time, it doesn't identify the open-source packages. So we enabled the scan in the containerize stage by executing the mend script and this populates the expected packages.

Options:

  • Skip the scanner in the compliance check stage (altogether preferably or scan main branch only). Add a check to containerize stage to scan main branch only.
    OR
  • Remove the scanner in containerize stage. 'Build' Operator before the scanner runs in compliance check stage, so that it can identify the packages. Scan main branch only.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants