.github/workflows/docker-scan.yml
@@ -51,7 +51,7 @@ scanners: vuln cache: false - name: Upload report to GitHub Security uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 # upload even if a preceding step failed, but not without a report to upload if: ${{ always() && hashFiles(format('trivy-{0}.sarif', matrix.tag)) != '' }} with: