-
Notifications
You must be signed in to change notification settings - Fork 10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Asking for clarification about SARIF report upload #29
Comments
Yes, the report gets uploaded in the run workflow and out of the box it is not uploaded to GH Security Advisory but it is available as an output of Tenant : That being said, currently the documentation illustrates an example where we use gitHub provided action : AI on us : Enhance documentation to illustrate integration of |
We did try the Here is the response from the workload:
|
Yes we are adhering to SARIF 2.1.0 guidelines "informationUri" is a valid property, but it seems like it can not be an empty URL. We will take an action item to fix the report structure and file a bug for now. Filed a Bug : #35 |
We have addressed above gaps and fixed the bug. @jasonloewen can you please try again ? |
The README states:
I was hoping that meant the violation report would get uploaded and imported to the GH Security Advisories, but I can only download the artifact from the link in the workflow. Is this the intended result?
The text was updated successfully, but these errors were encountered: