Skip to content

Commit 4dc5075

Browse files
authored
fix(daily-scan): point Trivy at published artifact dependencies (#117)
1 parent 09a75d4 commit 4dc5075

1 file changed

Lines changed: 5 additions & 5 deletions

File tree

.github/workflows/daily-scan.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
## Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.
22
## SPDX-License-Identifier: Apache-2.0
33
# Performs a daily scan of:
4-
# * The X-Ray Ruby SDK source code, using Trivy
4+
# * The X-Ray Ruby SDK published artifact dependencies, using Trivy
55
# * Project dependencies, using DependencyCheck
66
#
77
# Publishes results to CloudWatch Metrics.
@@ -81,24 +81,24 @@ jobs:
8181
if: ${{ steps.dep_scan.outcome != 'success' }}
8282
run: less dependency-check-report.html
8383

84-
- name: Perform high severity scan on built artifacts
84+
- name: Perform high severity scan on published artifact dependencies
8585
if: always()
8686
id: high_scan_latest
8787
uses: aquasecurity/trivy-action@97e0b3872f55f89b95b2f65b3dbab56962816478 # v0.34.2
8888
with:
8989
scan-type: 'fs'
90-
scan-ref: '.'
90+
scan-ref: 'scan-target/'
9191
severity: 'CRITICAL,HIGH'
9292
exit-code: '1'
9393
scanners: 'vuln'
9494

95-
- name: Perform low severity scan on built artifacts
95+
- name: Perform low severity scan on published artifact dependencies
9696
if: always()
9797
id: low_scan_latest
9898
uses: aquasecurity/trivy-action@97e0b3872f55f89b95b2f65b3dbab56962816478 # v0.34.2
9999
with:
100100
scan-type: 'fs'
101-
scan-ref: '.'
101+
scan-ref: 'scan-target/'
102102
severity: 'MEDIUM,LOW,UNKNOWN'
103103
exit-code: '1'
104104
scanners: 'vuln'

0 commit comments

Comments
 (0)