ci: file release Docker Scout results under main so the code scanning status and alerts stay current (#11338)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Alexander Petric
2026-09-25 11:41:19 +00:00
committed by GitHub
co-authored by Claude Opus 5.5
parent 733c119fd9
commit 16f3ee84f6
+7 -1
View File
@@ -454,12 +454,18 @@ jobs:
dockerhub-user: windmilllabs
dockerhub-password: ${{ secrets.DOCKER_PAT }}
# Filed under main, not under the release tag this job runs on. The scanned image is
# `-ee:main` and the Security tab only reads the default branch, so tag-only uploads
# left main's last Docker Scout result at 2025-01-29: the tool showed as failing and
# its alerts could never close. `sha` is the release commit, which is on main.
- name: Upload SARIF result
id: upload-sarif
if: ${{ github.event_name != 'pull_request_target' }}
uses: github/codeql-action/upload-sarif@v2
uses: github/codeql-action/upload-sarif@v4
with:
sarif_file: sarif.output.json
ref: refs/heads/main
sha: ${{ github.sha }}
# docker_scout_ee:
# runs-on: ubicloud