Skip to content

Commit

Permalink
Merge pull request #255 from bci-oss/bugfix/failing-trivy-scan
Browse files Browse the repository at this point in the history
prepare trivy scan for not failing on high findings
  • Loading branch information
agg3fe authored Nov 24, 2023
2 parents 27466f4 + 0e4d0b6 commit 65037a7
Showing 1 changed file with 10 additions and 7 deletions.
17 changes: 10 additions & 7 deletions .github/workflows/trivy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -43,15 +43,17 @@ jobs:
uses: actions/checkout@v3

- name: Run Trivy vulnerability scanner in repo mode
uses: aquasecurity/trivy-action@master
# uses: aquasecurity/trivy-action@master
uses: aquasecurity/[email protected]
with:
scan-type: "config"
# ignore-unfixed: true
exit-code: "1"
# exit-code: "1"
hide-progress: false
format: "sarif"
output: "trivy-results1.sarif"
severity: "CRITICAL,HIGH"
# severity: "CRITICAL,HIGH"
vuln-type: "os,library"

- name: Upload Trivy scan results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v2
Expand Down Expand Up @@ -79,16 +81,17 @@ jobs:
run: mvn clean package

- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master
# uses: aquasecurity/trivy-action@master
uses: aquasecurity/[email protected]
with:
image-ref: "tractusx/sldt-digital-twin-registry:latest"
# ignore-unfixed: true
exit-code: "1"
# exit-code: "1"
hide-progress: false
format: "sarif"
output: "trivy-results-registry.sarif"
severity: "CRITICAL,HIGH"

# severity: "CRITICAL,HIGH"
vuln-type: "os,library"
- name: Upload Trivy scan results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v2
if: always()
Expand Down

0 comments on commit 65037a7

Please sign in to comment.