-
Notifications
You must be signed in to change notification settings - Fork 4.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Robot account cannot access vulnerability report #17048
Comments
Hi @szczad , I think this is by design, as we can see that ResourceArtifactAddition is currently not listed as one of the 19 permissions: |
I'm not even trying to argue. The point is - my instance has OIDC enabled so I cannot add custom users anymore. Additionally, the robotic account cannot fetch scan results. It's not even a tie. I have been defeated by the design as my report generation tool cannot fetch the list of vulnerabilities from the CI pipeline. |
hi @szczad , |
Hi @MinerYang, The solution seems not so smooth, but I can confirm it works if the account has Thanks for the workaround, however, it would be nice to have it in the UI. |
If you are reporting a problem, please make sure the following information are provided:
Expected behavior and actual behavior:
A robot account cannot access a vulnerability report through API.
As a developer, I want to retrieve a scan report for further processing (report generation, auditing, etc.) using non-user account.
Currently, the account can start or stop the scan but cannot retrieve scan result.
Steps to reproduce the problem:
Please provide the steps to reproduce this problem
start scan
andstop scan
. No option forfetch scan
.Versions:
Please specify the versions of following systems.
The text was updated successfully, but these errors were encountered: