File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 9090 -PimageRegistry=${{ needs.build-vars.outputs.registry }}
9191 -PjdkVersion=${{ needs.build-vars.outputs.jvm-version }}
9292 -PimageTag=${{ needs.sha-tag.outputs.tag }}
93+
94+ vulnerability-scan :
95+ name : Scan for vulnerabilities
96+ runs-on : ubuntu-latest
97+ needs :
98+ - build-vars
99+ - sha-tag
100+ steps :
101+ - name : Run Trivy vulnerability scanner
102+ uses : aquasecurity/trivy-action@0.20.0
103+ with :
104+ image-ref : ${{ needs.build-vars.outputs.registry }}/${{ github.repository }}:${{ needs.sha-tag.outputs.tag }}
105+ format : table
106+ exit-code : 1
107+ ignore-unfixed : true
108+ vuln-type : os,library
109+ severity : CRITICAL,HIGH
110+
111+ - name : Upload Trivy scan results to GitHub Security tab
112+ uses : github/codeql-action/upload-sarif@v2
113+ if : always()
114+ with :
115+ sarif_file : trivy-results.sarif
You can’t perform that action at this time.
0 commit comments