diff --git a/.github/workflows/blackduck.yml b/.github/workflows/blackduck.yml index d07fdcd..6d6af77 100644 --- a/.github/workflows/blackduck.yml +++ b/.github/workflows/blackduck.yml @@ -17,7 +17,7 @@ jobs: - name: Checkout Source uses: actions/checkout@v3 - name: Black Duck Full Scan - if: ${{ github.event_name != 'pull_request' }} + #if: ${{ github.event_name != 'pull_request' }} uses: synopsys-sig/synopsys-action@v1.8.0 env: DETECT_PROJECT_NAME: "MED_ca-injector" @@ -27,19 +27,20 @@ jobs: blackduck_scan_full: true blackduck_scan_failure_severities: "BLOCKER,CRITICAL" blackduck_fixpr_enabled: true + blackduck_prComment_enabled: true blackduck_fixpr_maxCount: 5 blackduck_fixpr_filter_severities: "CRITICAL,HIGH" blackduck_fixpr_useUpgradeGuidance: "SHORT_TERM,LONG_TERM" github_token: ${{ secrets.GITHUB_TOKEN }} - - name: Black Duck PR Scan - if: ${{ github.event_name == 'pull_request' }} - uses: synopsys-sig/synopsys-action@v1.8.0 - env: - DETECT_PROJECT_NAME: "MED_ca-injector" - with: - blackduck_url: ${{ secrets.BLACKDUCK_URL }} - blackduck_token: ${{ secrets.BLACKDUCK_TOKEN }} - blackduck_scan_full: false - blackduck_prComment_enabled: true - github_token: ${{ secrets.GITHUB_TOKEN }} + # - name: Black Duck PR Scan + # if: ${{ github.event_name == 'pull_request' }} + # uses: synopsys-sig/synopsys-action@v1.8.0 + # env: + # DETECT_PROJECT_NAME: "MED_ca-injector" + # with: + # blackduck_url: ${{ secrets.BLACKDUCK_URL }} + # blackduck_token: ${{ secrets.BLACKDUCK_TOKEN }} + # blackduck_scan_full: false + # blackduck_prComment_enabled: true + # github_token: ${{ secrets.GITHUB_TOKEN }}