Skip to content

Fix Snyk SARIF uploads so alerts track per-image categories - #775

Merged
julienp merged 1 commit into
mainfrom
julienp/fix-snyk
Aug 14, 2026
Merged

Fix Snyk SARIF uploads so alerts track per-image categories#775
julienp merged 1 commit into
mainfrom
julienp/fix-snyk

Conversation

@julienp

@julienp julienp commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

Merge Snyk's per-target SARIF runs into a single run and strip automationDetails so GitHub uses our stable per-image categories again, mark the kitchen-sink scan continue-on-error (Snyk exits 1 on findings, so it failed nightly and never uploaded), and add a cleanup job that dismisses alerts in categories no longer produced by the scan matrix.

@julienp julienp added the impact/no-changelog-required This issue doesn't require a CHANGELOG update label Aug 12, 2026
Merge Snyk's per-target SARIF runs into a single run and strip automationDetails so GitHub uses our stable per-image categories again, mark the kitchen-sink scan continue-on-error (Snyk exits 1 on findings, so it failed nightly and never uploaded), and add a cleanup job that dismisses alerts in categories no longer produced by the scan matrix.
@julienp
julienp marked this pull request as ready for review August 12, 2026 13:45
@julienp
julienp requested a review from a team as a code owner August 12, 2026 13:45
@julienp
julienp merged commit aba3a36 into main Aug 14, 2026
54 checks passed
@julienp
julienp deleted the julienp/fix-snyk branch August 14, 2026 09:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

impact/no-changelog-required This issue doesn't require a CHANGELOG update

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants