Skip to content

ops(security): scan main on push too, so post-fix scans clear stale alerts#163

Merged
amavashev merged 1 commit into
mainfrom
ops/scan-on-main-push
May 3, 2026
Merged

ops(security): scan main on push too, so post-fix scans clear stale alerts#163
amavashev merged 1 commit into
mainfrom
ops/scan-on-main-push

Conversation

@amavashev
Copy link
Copy Markdown
Collaborator

Same systemic fix as cycles-server. Adds push: branches: [main] to pr-container-scan.yml so post-merge scans publish to the main-branch alert track (currently stale after every fix merge).

…lerts

Same systemic fix as cycles-server. Trivy alerts on refs/heads/main only
auto-close when a SARIF scan publishes against main itself; previously
the workflow only ran on PRs, leaving stale alerts after every merge.
Adds push:main trigger with same paths filter.
@amavashev amavashev enabled auto-merge (squash) May 3, 2026 11:04
@amavashev amavashev merged commit ce93ccf into main May 3, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant