docs: explain how dashboard settings override workflow inputs - #123
Open
David Larsen (dc-larsen) wants to merge 1 commit into
Open
David Larsen (dc-larsen) wants to merge 1 commit into
David Larsen (dc-larsen) wants to merge 1 commit into
Conversation
When an Enterprise org's dashboard configuration loads, it is merged over the INPUT_* environment variables the action sets, and unset dashboard fields come back as '' or false. A blank Dockerfiles field therefore wipes the workflow's dockerfiles input and no Dockerfile is scanned. The Container Security Pipeline and Dockerfile Auto-Discovery examples both hit this, while the docs only said dashboard values override "overlapping" inputs. - Add a Dashboard Settings and Workflow Inputs section: when the configuration loads, which settings blank fields override, the exceptions (blank rule lists, notifier fields, inputs with no dashboard field), the log lines that show which mode ran, and how to pass per-repository values as CLI flags by running the image directly - Flag both container examples and give the auto-discovery replacement step - Note that dockerfiles is a misconfiguration scan, base-image vulnerabilities need container_images, and paths are literal and repository-relative - Spell out the precedence in parameters.md and correct the README and Quick Start claims that the workflow never needs scanner inputs - Add a troubleshooting entry for inputs that have no effect
David Larsen (dc-larsen)
marked this pull request as ready for review
October 5, 2026 14:27
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
When an Enterprise organization's dashboard configuration loads, Socket Basics merges it over the
INPUT_*environment variables that carry the action'swith:inputs. Dashboard fields that were never filled in come back from the settings API as''orfalse, so they replace the workflow's values too. A blank Dockerfiles field wipesdockerfiles:and no Dockerfile is scanned.The docs said dashboard values override "overlapping"
with:values and that the workflow needs no changes. Two examples (Container Security Pipeline and Dockerfile Auto-Discovery) scan nothing for these organizations, with no error. This PR documents the actual precedence and gives a working pattern for per-repository values. It describes current behavior only. Whether blank dashboard fields should override workflow inputs at all is a separate code question.Changes
docs/github-action.md, Dashboard Settings and Workflow Inputs:socket-basicsscope)docker://ghcr.io/socketdev/socket-basics:<version>withargs:so--dockerfilesand--imagesapply after the dashboard merge. Also covers the two differences from the action: theaction.ymlrule-list defaults don't apply, and the image tag is bumped by hand.dockerfilesrunstrivy config(misconfigurations only). Base-image vulnerabilities need the built image incontainer_images. Paths are literal, comma-separated and repository-relative.docs/parameters.mdnow says thatwith:inputs are environment variables, when the dashboard layer applies, and how blank fields behave.Testing
pytest -q tests/: 489 passed.python3 scripts/check_release_docs.py --checkandpython3 scripts/sync_release_version.py --check: in sync at 3.4.0. The newdocker://references are tag-only, so the release docs sync picks them up.create_config_from_args(22/22 checks pass). The response used''andfalsefor unset keys, matching the settings endpoint's defaults.trivy_vuln_enabledoff, Trivy never loads. With it on, Trivy logsNo Dockerfiles specified, skipping Trivy Dockerfile scanning.trueinputs: SAST language, secrets, verbose and console output.<language>_enabled_rulesis skipped.trivy_vuln_enabledandchanged_filescome from the workflow.--dockerfilesand--imagesbeat blank dashboard fields, and the other dashboard settings still apply. Without theaction.ymldefaults, Java uses the 19-rule list fromconnectors.yaml.docker://step pattern with--dockerfilesand--imageshas been confirmed working in a GitHub Actions workflow on 3.4.0.docker buildx imagetools inspect ghcr.io/socketdev/socket-basics:3.4.0prints the published digest.Note
Low Risk
Documentation-only changes with no runtime or configuration code modifications.
Overview
This PR corrects misleading guidance that Enterprise customers need no workflow changes when using the Socket Dashboard. It documents that loaded dashboard config wins over
with:inputs, including empty dashboard fields and off toggles, which can silently disable scanners (notably blank Dockerfiles / Container Images wipingdockerfilesandcontainer_images).docs/github-action.mdadds Dashboard Settings and Workflow Inputs (load conditions, override rules, exceptions, log lines), Setting Values Per Repository viadocker://ghcr.io/socketdev/socket-basicswithargs:for per-repo overrides, IMPORTANT notes on container and auto-discovery examples, clearerdockerfilesvscontainer_imagesbehavior, and troubleshooting for inputs that seem ignored.docs/parameters.mdupdates Configuration Precedence so action inputs map toINPUT_*env vars and documents blank-field behavior plus the CLI-only override path.README.mdaligns Quick Start and Enterprise copy with the same precedence story and adds a troubleshooting bullet.Reviewed by Cursor Bugbot for commit 2b8f601. Configure here.