From 16f3ee84f6cdcbb5781b6cae790614b30f28ecc9 Mon Sep 17 00:00:00 2001 From: Alexander Petric Date: Fri, 25 Sep 2026 07:41:19 -0400 Subject: [PATCH] ci: file release Docker Scout results under main so the code scanning status and alerts stay current (#11338) Co-authored-by: Claude Opus 5.5 (1M context) --- .github/workflows/docker-image.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/docker-image.yml b/.github/workflows/docker-image.yml index b468387057..c94521d332 100644 --- a/.github/workflows/docker-image.yml +++ b/.github/workflows/docker-image.yml @@ -454,12 +454,18 @@ jobs: dockerhub-user: windmilllabs dockerhub-password: ${{ secrets.DOCKER_PAT }} + # Filed under main, not under the release tag this job runs on. The scanned image is + # `-ee:main` and the Security tab only reads the default branch, so tag-only uploads + # left main's last Docker Scout result at 2025-01-29: the tool showed as failing and + # its alerts could never close. `sha` is the release commit, which is on main. - name: Upload SARIF result id: upload-sarif if: ${{ github.event_name != 'pull_request_target' }} - uses: github/codeql-action/upload-sarif@v2 + uses: github/codeql-action/upload-sarif@v4 with: sarif_file: sarif.output.json + ref: refs/heads/main + sha: ${{ github.sha }} # docker_scout_ee: # runs-on: ubicloud