diff --git a/.github/workflows/vulnerability-scan.yml b/.github/workflows/vulnerability-scan.yml index b7d6e6484dd6a..f47aafc4de28b 100644 --- a/.github/workflows/vulnerability-scan.yml +++ b/.github/workflows/vulnerability-scan.yml @@ -9,7 +9,6 @@ jobs: snyk: name: Snyk Scan runs-on: ubuntu-latest - continue-on-error: true steps: - name: Checkout code uses: actions/checkout@master @@ -28,10 +27,12 @@ jobs: - name: Format Snyk Message uses: sergeysova/jq-action@v2 + continue-on-error: true with: cmd: jq -r '.vulnerabilities[] | "* **\(.severity)** - [\(.identifiers.CVE[0])] \(.title) in `\(.moduleName)` v\(.version). Fixed in \(.fixedIn)"' snyk.json >> snyk.txt - name: Determine whether to comment + continue-on-error: true run: | if [[ $(wc -l < snyk.txt) -gt 1 ]]; then exit 0; fi exit 1 @@ -45,7 +46,6 @@ jobs: trivy: name: Trivy Scan runs-on: ubuntu-20.04 - continue-on-error: true steps: - name: Checkout code uses: actions/checkout@v3 @@ -70,10 +70,12 @@ jobs: - name: Format Trivy Message uses: sergeysova/jq-action@v2 + continue-on-error: true with: cmd: jq -r '.Results[] | .Vulnerabilities[] | "* **\(.Severity)** [\(.Title)](\(.PrimaryURL)) in `\(.PkgName)` v\(.InstalledVersion). Fixed in v\(.FixedVersion)"' trivy.json >> trivy.txt - name: Determine whether to comment + continue-on-error: true run: | if [[ $(wc -l < trivy.txt) -gt 1 ]]; then exit 0; fi exit 1