diff --git a/.github/workflows/Scan-with-Snyk-and-Monitor.yaml b/.github/workflows/Scan-with-Snyk-and-Monitor.yaml index 7bb2ffe..3084f3f 100644 --- a/.github/workflows/Scan-with-Snyk-and-Monitor.yaml +++ b/.github/workflows/Scan-with-Snyk-and-Monitor.yaml @@ -7,8 +7,13 @@ jobs: - uses: actions/checkout@master - name: Run Snyk to check for vulnerabilities uses: snyk/actions/node@master + continue-on-error: true # To make sure that SARIF upload gets called even if there are vulnerabilities env: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} with: - args: --all-projects --severity-threshold=critical - command: monitor \ No newline at end of file + args: --all-projects --severity-threshold=critical --sarif-file-output=snyk.sarif + command: monitor + - name: Upload result to GitHub Code Scanning + uses: github/codeql-action/upload-sarif@v2 + with: + sarif_file: snyk.sarif \ No newline at end of file