Skip to content

docs: document Docker Hub image and fix SARIF upload path - #194

Merged
advaitpatel merged 1 commit into
mainfrom
docs/dockerhub-and-sarif-fix
Sep 21, 2026
Merged

advaitpatel merged 1 commit into
mainfrom
docs/dockerhub-and-sarif-fix

Conversation

@advaitpatel

Copy link
Copy Markdown
Collaborator

Summary

  • Documents the owasp/docksec Docker Hub image alongside the existing GHCR image in README and the website (getting-started, evaluation-guide), since both are now published from the same release build
  • Fixes the SARIF example in README: upload-sarif was pointed at ~/.docksec/results, a path inside the Action container rather than on the runner, so the SARIF file was never found and no findings were uploaded (closes README SARIF example points upload-sarif at a container-only path, so no findings are uploaded #192)

Test plan

  • Confirm the corrected SARIF example produces a findings upload to the Security tab when run in a workflow

README and the website now mention owasp/docksec on Docker Hub
alongside the GHCR image, since both are published from the same
release build.

Also fixes the SARIF upload example in README (closes #192): it
pointed upload-sarif at ~/.docksec/results, a path inside the Action
container rather than on the runner, so the SARIF file was never
found and no findings were ever uploaded. Points output_dir and
sarif_file at a workspace-relative path instead, and adds a category
so multiple DockSec scans in one workflow don't overwrite each
other's upload.
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Sep 21, 2026
@advaitpatel
advaitpatel merged commit 84c2696 into main Sep 21, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

README SARIF example points upload-sarif at a container-only path, so no findings are uploaded

1 participant