Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
The PR pipeline already runs Snyk, but doesn't upload the results anywhere. Run Snyk in the push pipeline as well and upload the results to snyk.io. Note: we should not upload to Snyk from the PR pipeline. Each PR would overwrite the Snyk results from other PRs. By uploading only in the push pipeline, the results will at least always reflect the state in 'main'. The results can be found in the 'konflux-ci/build-definitions' project in the Snyk organization associated with the Snyk token used by the pipeline (currently the 'developer-red-hat-trusted-application-pipeline' organization). Signed-off-by: Adam Cmiel <[email protected]>
- Loading branch information