Skip to content

PSP-11210: SPIKE: Investigate only running image scanning tools when changes are made to dependencies.#5244

Merged
areyeslo merged 3 commits intobcgov:devfrom
areyeslo:PSP-11210-RunImageScanning-Dependencies
Mar 9, 2026
Merged

PSP-11210: SPIKE: Investigate only running image scanning tools when changes are made to dependencies.#5244
areyeslo merged 3 commits intobcgov:devfrom
areyeslo:PSP-11210-RunImageScanning-Dependencies

Conversation

@areyeslo
Copy link
Collaborator

@areyeslo areyeslo commented Mar 5, 2026

Only run image scanning when changes are made to dependencies.

Run Scan container images when changes in package.json:
https://github.com/areyeslo/PSP/actions/runs/22738809586

No changes skips Scan container images:
https://github.com/areyeslo/PSP/actions/runs/22734826069

Jira

@areyeslo areyeslo self-assigned this Mar 5, 2026
@areyeslo areyeslo added the enhancement New feature or request label Mar 5, 2026
@areyeslo areyeslo force-pushed the PSP-11210-RunImageScanning-Dependencies branch from e368bbc to e7ccc75 Compare March 5, 2026 23:27
@sonarqubecloud
Copy link

sonarqubecloud bot commented Mar 5, 2026

Copy link
Collaborator

@asanchezr asanchezr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.
One question - we also scan images in the TEST deployment pipeline (retag-dev-to-test.yml). Shouldn't we also make changes there?

@areyeslo areyeslo added this pull request to the merge queue Mar 9, 2026
Merged via the queue into bcgov:dev with commit 333033a Mar 9, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants