Skip to content

Commit

Permalink
Merge pull request #574 from Automattic/fix/ci-comments
Browse files Browse the repository at this point in the history
ci: allow comments from PRs by Dependabot
  • Loading branch information
sjinks authored Oct 31, 2023
2 parents 5d730a2 + ddf3020 commit b6b6935
Showing 1 changed file with 4 additions and 4 deletions.
8 changes: 4 additions & 4 deletions .github/actions/build-docker-image/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -96,22 +96,22 @@ runs:
format: template
template: "@.github/actions/build-docker-image/markdown.tpl"
output: trivy.md
if: github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.event.pull_request.base.repo.full_name && github.event.sender.login != 'dependabot[bot]'
if: github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.event.pull_request.base.repo.full_name

- name: Security Scan
uses: aquasecurity/trivy-action@master
with:
image-ref: ${{ inputs.primaryTag }}
format: table
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name || github.event.sender.login == 'dependabot[bot]'
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name

- name: Find Trivy Scan Report comment
uses: peter-evans/find-comment@v2
id: fc
with:
issue-number: ${{ github.event.pull_request.number }}
body-includes: ${{ inputs.primaryTag }}
if: github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.event.pull_request.base.repo.full_name && github.event.sender.login != 'dependabot[bot]'
if: github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.event.pull_request.base.repo.full_name

- name: Create or update comment
uses: peter-evans/create-or-update-comment@v3
Expand All @@ -120,4 +120,4 @@ runs:
issue-number: ${{ github.event.pull_request.number }}
body-path: trivy.md
edit-mode: replace
if: github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.event.pull_request.base.repo.full_name && github.event.sender.login != 'dependabot[bot]'
if: github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.event.pull_request.base.repo.full_name

0 comments on commit b6b6935

Please sign in to comment.