From 40eb87806f6836e93db83f0cfbca8acb7c463299 Mon Sep 17 00:00:00 2001 From: Chris Gianelloni Date: Wed, 26 Nov 2025 12:03:28 -0500 Subject: [PATCH] ci: reduce os package scan noise Signed-off-by: Chris Gianelloni --- .github/workflows/publish.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index d49bb2e..093bb14 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -64,6 +64,8 @@ jobs: scan-ref: 'ghcr.io/blinklabs-io/openvpn:${{ env.FIRST_TAG }}' format: 'sarif' output: 'trivy-results-${{ env.FIRST_TAG }}.sarif' + ignore-unfixed: true + severity: 'HIGH,CRITICAL' - name: Upload Trivy scan results to GitHub Security tab uses: github/codeql-action/upload-sarif@fdbfb4d2750291e159f0156def62b853c2798ca2 # v4.31.5 if: always()