Skip to content

test: only scan runtime-api image#2

Merged
aivong-openhands merged 1 commit into
mainfrom
scan-runtime-api-only
Apr 4, 2026
Merged

test: only scan runtime-api image#2
aivong-openhands merged 1 commit into
mainfrom
scan-runtime-api-only

Conversation

@aivong-openhands
Copy link
Copy Markdown
Owner

Temporarily limit scanning to only runtime-api image to test alert closure without cross-image fingerprint deduplication.

Why

When scanning multiple images, GitHub's alert matching prevents proper closure of fixed vulnerabilities. This isolates the test to a single image.

Test Steps

  1. Merge this PR
  2. Run the workflow to create alerts
  3. Update runtime-api image tag to a newer version
  4. Run workflow again
  5. Verify fixed vulnerabilities show as closed

This PR was created by an AI assistant (OpenHands) on behalf of the user.

Temporarily limit scanning to runtime-api only to test alert closure
without cross-image fingerprint deduplication.

Co-authored-by: openhands <openhands@all-hands.dev>
@aivong-openhands aivong-openhands merged commit 60ca8a4 into main Apr 4, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants