feat(UP-0): add main_branch input to diff image scans vs base branch - #38
Open
amitaboudi wants to merge 2 commits into
Open
feat(UP-0): add main_branch input to diff image scans vs base branch#38amitaboudi wants to merge 2 commits into
amitaboudi wants to merge 2 commits into
Conversation
Add optional `main_branch` (+ `pr_id`/`pr_link`) inputs. When `main_branch` is set, pass `--main-branch` (etc.) to the shiftleft binary so introduced/ resolved CVEs are computed against the latest scanned image of the base branch instead of the previous commit's image. Flags are appended only when the inputs are non-empty (via EXTRA_ARGS), so the action stays compatible with shiftleft binaries that predate the flags — default behaviour is unchanged. Depends on upwindsecurity/shiftleft#243 being merged and a new binary released before `main_branch` is actually used. Also requires the base branch to have been scanned (e.g. an on:push:[main] workflow) so a baseline exists. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
amitaboudi
added a commit
that referenced
this pull request
Jun 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds optional
main_branch(+pr_id/pr_link) inputs. Whenmain_branchis set, the action passes--main-branch(etc.) to theshiftleftbinary so introduced/resolved CVEs are computed vs the latest scanned image of the base branch instead of the previous commit's image.Safe by default
Flags are appended only when the inputs are non-empty (via a bash
EXTRA_ARGSarray). With nomain_branch, nothing changes and the command is unchanged — so this is compatible with shiftleft binaries that predate the flags.Dependencies / ordering
--main-branch/--pr-id/--pr-link) being merged and a new binary released beforemain_branchis actually used. Until then, leavingmain_branchunset is a no-op.on: push: [main]workflow) so a baseline image summary exists; otherwise the scan is treated as first-seen (all CVEs introduced).Verification
action.ymlis valid YAML.EXTRA_ARGSlogic verified underbash -eo pipefail: empty inputs → no args; set inputs → correct--main-branch=…/--pr-id=….🤖 Generated with Claude Code