diff --git a/.github/actions/scan-dependencies/action.yaml b/.github/actions/scan-dependencies/action.yaml index 351ed51..9894214 100644 --- a/.github/actions/scan-dependencies/action.yaml +++ b/.github/actions/scan-dependencies/action.yaml @@ -30,6 +30,13 @@ runs: run: | curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh \ | sudo sh -s -- -b /usr/bin + - name: "Display vulnerabilities table" + uses: anchore/scan-action@v7 + with: + sbom: ./sbom-repository-report.json + severity-cutoff: high + output-format: table + fail-build: false - name: "Scan vulnerabilities" shell: bash run: | diff --git a/scripts/config/grype.yaml b/scripts/config/grype.yaml index 07484ca..0fecf29 100644 --- a/scripts/config/grype.yaml +++ b/scripts/config/grype.yaml @@ -1,5 +1,6 @@ # If using SBOM input, automatically generate CPEs when packages have none add-cpes-if-none: true +fail-on-severity: high # ignore: # # This is the full set of supported rule fields: # - vulnerability: CVE-2008-4318