Add job deploy #83
main.yml
on: pull_request
Secrets scanning (Gitleaks)
10s
Build + SBOM
21s
Supply chain gate (cosign sobre SBOM)
0s
DAST (OWASP ZAP baseline)
0s
Annotations
1 error
|
Container & deps scan (Trivy)
Aborting upload: only one run of the codeql/analyze or codeql/upload-sarif actions is allowed per job per tool/category. The easiest fix is to specify a unique value for the `category` input. If .runs[].automationDetails.id is specified in the sarif file, that will take precedence over your configured `category`. Category: (.github/workflows/main.yml:container_scan/) Tool: (Trivy)
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
gitleaks-results.sarif
Expired
|
6.71 KB |
sha256:48489247d98f9784ee2295395916a7fdc3cde58991b3392c11cec1f6f1d7b4d6
|
|
|
sbom.spdx.json
Expired
|
83.9 KB |
sha256:64f883b1459d5984ef8834c9eb92709f09f7353548a14a35b30cb2c072805975
|
|