You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Incremental scan output summary can be misleading to user by showing 0 vulnerabilities when other vulnerabilities already exist. Could we have an option to not generate the summary.
Propose a solution
Add a new parameter to the action, to disable the creation of a workflow summary.
The text was updated successfully, but these errors were encountered:
Thank you for bringing this to our attention. To ensure I understand correctly, are you referencing instances where the Incremental scan shows "0 vulnerabilities" even when vulnerabilities exist from previous scans? Is this in comparison to the results from the last full scan?
Furthermore, could you provide more insight into your perspective on the value of a scan that doesn't display any results?
The issue occurs when a scan is launched asynchronously:
By the time the CLI tries to retrieve scan's results, it gets nothing (as the scan is not complete yet), and generate an output with 0 vulnerabilities.
I already proposed a simple code change to prevent this behaviour (see PR #134)
Is your request related to a workflow problem?
Incremental scan output summary can be misleading to user by showing 0 vulnerabilities when other vulnerabilities already exist. Could we have an option to not generate the summary.
Propose a solution
Add a new parameter to the action, to disable the creation of a workflow summary.
The text was updated successfully, but these errors were encountered: