Disabling both Trivy Scanning and AI Code review

You can disable the Trivy security scan and AI-powered code review that Code Genie runs automatically on pull request creation or update.

About this task

By default, Code Genie runs a Trivy security scan and an AI-powered code review every time a pull request is created or updated. To turn off these checks, comment out the corresponding entries in the "pull-request" array of .devops-loop/code-config.jsonc.

Procedure

  1. Open .devops-loop/code-config.jsonc in the Control repository.
  2. Locate the "pull-request" array.
  3. Enclose the TrivyScan entry and the Copilot entry in block comments (/* */).
  4. Save the file.

Results

With no active entries in the "pull-request" array, Code Genie does not run a security scan or a code review when a pull request is created or updated.

Note:
Disabling Trivy scanning and code review affects only the "pull-request" array. It does not affect the Plan work item implementation ("workitem" array).

Example

The following example shows the "pull-request" array with Trivy scanning and code review disabled:

"pull-request": [
     /*{
       "dev-container": "TrivyScan",
       "interactive": false,
       "custom-commands": [
         {
           "run-trivy": "cp /opt/run-trivy.sh /usr/code/ && chmod +x /usr/code/run-trivy.sh && REPO_URL=https://${platform-fqdm}/control/${repo-owner}/${repo}/src/branch/${pr-branch}/ /usr/code/run-trivy.sh ${code-folder} ${result-json} --reject=high --trivyArgs=\"--scanners vuln,misconfig,secret,license --license-full --severity UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL\""
         }
       ]
     },
     {
       "dev-container": "Copilot",
       "interactive": true,
       "custom-commands": [
         {
           "code-review-command": "export GH_TOKEN=${loop_property:copilotclitoken} && cp /opt/run-copilot.ts /usr/code/ && tsx /usr/code/run-copilot.ts --prompt-file=${promptFile} --llm_args=\"--allow-all-tools --model claude-sonnet-4.5\""
         }
       ]
     }*/
     /* Uncomment this block to use IBM Bob Shell for code reviews
     ,{
       "dev-container": "Bob",
       "interactive": true,
       "custom-commands": [
         {
           "code-review-command": "export BOBSHELL_API_KEY=${loop_property:bobtoken} && cp /opt/run-bob.ts /usr/code/ && tsx /usr/code/run-bob.ts --prompt-file=${promptFile} --bob_args=\"--yolo --accept-license --auth-method api-key\""
         }
       ]
     }*/
   ]