scout-action
scout-action copied to clipboard
1.13.0 broke our workflow, downstream auth error
1.12.0 does not have this issue
our workflow goes:
- login to ghcr.io
- login to docker hub where we have scout access
- build image
- push image to ghcr.io
- scan image
this is the error we see on 1.13.0 we are not seeing on 1.12.0
cves
...Storing image for indexing
✓ Image stored for indexing
...Indexing
✓ Indexed 412 packages
✓ Provenance obtained from attestation
Error: could not list CVEs for the image: API operation failed: Message: Not allowed, Locations: [], Extensions: map[arguments:map[context:$context query:map[imageCoords:map[digest:$digest hostname:$hostname repository:$repository] includeExcepted:$includeExcepted packageUrls:$purls]] code:DOWNSTREAM_SERVICE_ERROR status:FORBIDDEN], Path: [vulnerabilitiesByPackageForImageCoords]