Skip to content

Commit 3e04555

Browse files
authored
Merge pull request #487 from aws/trivy-scan-published-artifacts
fix(daily-scan): point Trivy at published artifact dependencies
2 parents 3817250 + 41cf1dc commit 3e04555

1 file changed

Lines changed: 5 additions & 5 deletions

File tree

.github/workflows/daily-scan.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
## Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.
22
## SPDX-License-Identifier: Apache-2.0
33
# Performs a daily scan of:
4-
# * The X-Ray Python SDK source code, using Trivy
4+
# * The X-Ray Python SDK published artifact dependencies, using Trivy
55
# * Project dependencies, using DependencyCheck
66
#
77
# Publishes results to CloudWatch Metrics.
@@ -79,24 +79,24 @@ jobs:
7979
if: ${{ steps.dep_scan.outcome != 'success' }}
8080
run: less dependency-check-report.html
8181

82-
- name: Perform high severity scan on built artifacts
82+
- name: Perform high severity scan on published artifact dependencies
8383
if: always()
8484
id: high_scan_latest
8585
uses: aquasecurity/trivy-action@97e0b3872f55f89b95b2f65b3dbab56962816478 # v0.34.2
8686
with:
8787
scan-type: 'fs'
88-
scan-ref: '.'
88+
scan-ref: 'scan-target/'
8989
severity: 'CRITICAL,HIGH'
9090
exit-code: '1'
9191
scanners: 'vuln'
9292

93-
- name: Perform low severity scan on built artifacts
93+
- name: Perform low severity scan on published artifact dependencies
9494
if: always()
9595
id: low_scan_latest
9696
uses: aquasecurity/trivy-action@97e0b3872f55f89b95b2f65b3dbab56962816478 # v0.34.2
9797
with:
9898
scan-type: 'fs'
99-
scan-ref: '.'
99+
scan-ref: 'scan-target/'
100100
severity: 'MEDIUM,LOW,UNKNOWN'
101101
exit-code: '1'
102102
scanners: 'vuln'

0 commit comments

Comments
 (0)