From a780e1cdf35076be8fd0328cf5d3dea568ad22dc Mon Sep 17 00:00:00 2001 From: Mitch Zhu Date: Thu, 20 Feb 2025 23:30:10 +0000 Subject: [PATCH] Adjuest binskim options --- .github/workflows/binskim.yaml | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/.github/workflows/binskim.yaml b/.github/workflows/binskim.yaml index e2d1ed603fce..3d2979d64d68 100644 --- a/.github/workflows/binskim.yaml +++ b/.github/workflows/binskim.yaml @@ -73,7 +73,8 @@ jobs: echo "Error: kata-agent binary not found!" exit 1 fi - binskim analyze "$KATA_AGENT_PATH" --output binskim-agent.sarif --verbose + binskim analyze "$KATA_AGENT_PATH" --output binskim-agent.sarif --level Error --kind Pass;Fail + #- name: Scan runtime binary # run: | @@ -82,7 +83,7 @@ jobs: # echo "Error: kata-runtime binary not found!" # exit 1 # fi - # binskim analyze "$KATA_RUNTIME_PATH" --output binskim-runtime.sarif --verbose + # binskim analyze "$KATA_RUNTIME_PATH" --output binskim-agent.sarif --level Error --kind Pass;Fail - name: Scan tardev-snapshotter binary run: | @@ -91,7 +92,7 @@ jobs: echo "Error: tardev-snapshotter binary not found!" exit 1 fi - binskim analyze "$TARDEV_SNAPSHOTTER_PATH" --output binskim-snapshotter.sarif --verbose + binskim analyze "$TARDEV_SNAPSHOTTER_PATH" --output binskim-agent.sarif --level Error --kind Pass;Fail - name: Scan overlay binary run: | @@ -100,7 +101,7 @@ jobs: echo "Error: kata-overlay binary not found!" exit fi - binskim analyze "$OVERLAY_PATH" --output binskim-overlay.sarif --verbose + binskim analyze "$OVERLAY_PATH" --output binskim-agent.sarif --level Error --kind Pass;Fail # Validate SARIF reports before uploading - name: Validate SARIF Reports