Skip to content

Docker Scout integration? #110

@mathieu-benoit

Description

@mathieu-benoit

Description

It would be very convenient to have Docker Scout embedded, as optional, in this reusable workflow.

For example, one of the common use case is to scan CVEs and upload the SARIF outputs to GitHub Security panel.

Different other options would be very beneficial too:

  • org --> to evaluate policies
  • quickview action and optionally write summary as a PR comment
  • compare action with another image and optionally write the comparison table as a PR comment

Note: we could have another job doing that, but for example in a PR, if we do push: false but still want to use Docker Scout, it's very complex to have this in place, as an end user.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions