Disabling both Trivy Scanning and AI Code review
You can disable the Trivy security scan and AI-powered code review that Code Genie runs automatically on pull request creation or update.
About this task
By default, Code Genie runs a Trivy security scan and an AI-powered code review every
time a pull request is created or updated. To turn off these checks, comment out the
corresponding entries in the "pull-request" array of
.devops-loop/code-config.jsonc.
Procedure
- Open .devops-loop/code-config.jsonc in the Control repository.
-
Locate the
"pull-request"array. -
Enclose the
TrivyScanentry and theCopilotentry in block comments (/* */). - Save the file.
Results
With no active entries in the "pull-request" array, Code Genie does
not run a security scan or a code review when a pull request is created or
updated.
"pull-request" array. It does not affect the Plan
work item implementation ("workitem" array).Example
The following example shows the "pull-request" array with Trivy
scanning and code review disabled:
"pull-request": [
/*{
"dev-container": "TrivyScan",
"interactive": false,
"custom-commands": [
{
"run-trivy": "cp /opt/run-trivy.sh /usr/code/ && chmod +x /usr/code/run-trivy.sh && REPO_URL=https://${platform-fqdm}/control/${repo-owner}/${repo}/src/branch/${pr-branch}/ /usr/code/run-trivy.sh ${code-folder} ${result-json} --reject=high --trivyArgs=\"--scanners vuln,misconfig,secret,license --license-full --severity UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL\""
}
]
},
{
"dev-container": "Copilot",
"interactive": true,
"custom-commands": [
{
"code-review-command": "export GH_TOKEN=${loop_property:copilotclitoken} && cp /opt/run-copilot.ts /usr/code/ && tsx /usr/code/run-copilot.ts --prompt-file=${promptFile} --llm_args=\"--allow-all-tools --model claude-sonnet-4.5\""
}
]
}*/
/* Uncomment this block to use IBM Bob Shell for code reviews
,{
"dev-container": "Bob",
"interactive": true,
"custom-commands": [
{
"code-review-command": "export BOBSHELL_API_KEY=${loop_property:bobtoken} && cp /opt/run-bob.ts /usr/code/ && tsx /usr/code/run-bob.ts --prompt-file=${promptFile} --bob_args=\"--yolo --accept-license --auth-method api-key\""
}
]
}*/
]