Version of the pipe: 3.2.0
Hello, I am using the above version of the git-secret-scan to create a pipeline to scan for any committed secrets in a pull request.
While I got the pipe to run and generate a report, I am having trouble getting the inline annotations to work. We have the pipe steps defined as a shared pipeline, like this:
export: true
definitions:
pipelines:
secret-scanning:
- step:
name: "secret-scanning"
script:
- echo "Running secret scanning against the PR"
- git fetch origin $BITBUCKET_PR_DESTINATION_BRANCH
- pipe: atlassian/git-secrets-scan:3.2.0
variables:
DEBUG: "true"
GITLEAKS_EXTRA_ARGS:
- "--redact"
- "--log-opts=origin/$BITBUCKET_PR_DESTINATION_BRANCH..HEAD"
And the consuming repositories would call them like this:
clone:
depth: full
definitions:
imports:
infra-build-pipelines: infra-build-pipelines:feature/{branchname}:secret-scanning-pipelines.yml
pipelines:
pull-requests:
'**':
import: secret-scanning@infra-build-pipelines
Is there something I am missing here, perhaps an extra argument I need to add? The documentation keeps pointing that the pipe should take care of the report generation and inline annotations, but we cannot get the annotations to work. We've checked to make sure that the annotation feature is turned on.