Skip to content

Commit 89410be

Browse files
committed
chore(ci): ignore unirtm_data directories in trivy scanning to prevent false positive secrets alerts
Fixes: https://github.com/snowdreamtech/UniRTM/security/code-scanning/28
1 parent 79f5b90 commit 89410be

3 files changed

Lines changed: 6 additions & 0 deletions

File tree

.github/workflows/cd.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -163,6 +163,7 @@ jobs:
163163
output: "trivy-results.sarif"
164164
severity: "CRITICAL,HIGH,MEDIUM,LOW"
165165
exit-code: "1"
166+
skip-dirs: "unirtm_data,cmd/unirtm_data"
166167

167168
- name: "📤 Upload Security Audit (SARIF)"
168169
uses: github/codeql-action/upload-sarif@95e58e9a2cdfd71adc6e0353d5c52f41a045d225 # v4.35.2

.github/workflows/ci.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -474,6 +474,7 @@ jobs:
474474
output: "trivy-results.sarif"
475475
severity: "CRITICAL,HIGH,MEDIUM,LOW"
476476
exit-code: "1"
477+
skip-dirs: "unirtm_data,cmd/unirtm_data"
477478

478479
- name: "📤 Upload Security Audit (SARIF)"
479480
uses: github/codeql-action/upload-sarif@95e58e9a2cdfd71adc6e0353d5c52f41a045d225 # v4.35.2

trivy.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
scan:
2+
skip-dirs:
3+
- "unirtm_data"
4+
- "cmd/unirtm_data"

0 commit comments

Comments
 (0)