diff --git a/.github/workflows/amazon-cloudwatch-observability-image-scan.yaml b/.github/workflows/amazon-cloudwatch-observability-image-scan.yaml index 61e7540..5e0224d 100644 --- a/.github/workflows/amazon-cloudwatch-observability-image-scan.yaml +++ b/.github/workflows/amazon-cloudwatch-observability-image-scan.yaml @@ -88,6 +88,7 @@ jobs: image: ${{ steps.registry.outputs.result }}/${{ steps.repository.outputs.result }}:${{ steps.tag.outputs.result }} severity_threshold: HIGH annotations: true + - run: echo $(jq -r . ${{ steps.scan.outputs.json }}) # from https://stackoverflow.com/questions/61919141/read-json-file-in-github-actions - run: echo "SCAN_RESULT=$(jq -r '.[] | "**\(.ArtifactName)**:\n" + ( .Results // empty | .[] | select(.Vulnerabilities != null) | .Vulnerabilities[] | "- \(.VulnerabilityID)" ) | @text' ${{ steps.scan.outputs.json }})" >> $GITHUB_ENV if: success() || failure()