@@ -34,40 +34,52 @@ jobs:
3434
3535 - name : Create SBOM with Trivy
3636 uses : aquasecurity/trivy-action@0.33.1
37+ env :
38+ TRIVY_SHOW_SUPPRESSED : 1
39+ TRIVY_IGNOREFILE : " ./.trivyignore.yaml"
3740 with :
38- scan-type : ' fs '
39- format : ' spdx-json'
41+ scan-type : " fs "
42+ format : " spdx-json"
4043 output : " defguard-gateway-${{ steps.vars.outputs.VERSION }}.sbom.json"
41- scan-ref : ' . '
44+ scan-ref : " . "
4245 severity : " CRITICAL,HIGH,MEDIUM,LOW"
4346 scanners : " vuln"
4447
4548 - name : Create docker image SBOM with Trivy
4649 uses : aquasecurity/trivy-action@0.33.1
50+ env :
51+ TRIVY_SHOW_SUPPRESSED : 1
52+ TRIVY_IGNOREFILE : " ./.trivyignore.yaml"
4753 with :
4854 image-ref : " ghcr.io/defguard/gateway:${{ steps.vars.outputs.VERSION }}"
49- scan-type : ' image'
50- format : ' spdx-json'
55+ scan-type : " image"
56+ format : " spdx-json"
5157 output : " defguard-gateway-${{ steps.vars.outputs.VERSION }}-docker.sbom.json"
5258 severity : " CRITICAL,HIGH,MEDIUM,LOW"
5359 scanners : " vuln"
5460
5561 - name : Create security advisory file with Trivy
5662 uses : aquasecurity/trivy-action@0.33.1
63+ env :
64+ TRIVY_SHOW_SUPPRESSED : 1
65+ TRIVY_IGNOREFILE : " ./.trivyignore.yaml"
5766 with :
58- scan-type : ' fs '
59- format : ' json'
67+ scan-type : " fs "
68+ format : " json"
6069 output : " defguard-gateway-${{ steps.vars.outputs.VERSION }}.advisories.json"
61- scan-ref : ' . '
70+ scan-ref : " . "
6271 severity : " CRITICAL,HIGH,MEDIUM,LOW"
6372 scanners : " vuln"
6473
6574 - name : Create docker image security advisory file with Trivy
6675 uses : aquasecurity/trivy-action@0.33.1
76+ env :
77+ TRIVY_SHOW_SUPPRESSED : 1
78+ TRIVY_IGNOREFILE : " ./.trivyignore.yaml"
6779 with :
6880 image-ref : " ghcr.io/defguard/gateway:${{ steps.vars.outputs.VERSION }}"
69- scan-type : ' image'
70- format : ' json'
81+ scan-type : " image"
82+ format : " json"
7183 output : " defguard-gateway-${{ steps.vars.outputs.VERSION }}-docker.advisories.json"
7284 severity : " CRITICAL,HIGH,MEDIUM,LOW"
7385 scanners : " vuln"
0 commit comments