Skip to content

Fix and modernize release workflows, complete ghcr.io migration, and parameterize jobs for easy fork usage #4322

Fix and modernize release workflows, complete ghcr.io migration, and parameterize jobs for easy fork usage

Fix and modernize release workflows, complete ghcr.io migration, and parameterize jobs for easy fork usage #4322

Workflow file for this run

---
name: trivy-fs
on:
push:
branches:
- main
pull_request:
branches:
- main
schedule:
- cron: "50 22 * * *"
concurrency:
group: ${{ github.workflow }}-${{ github.event_name }}-${{ github.event.pull_request.number || github.run_id }}
cancel-in-progress: true
permissions:
contents: read
jobs:
code-scan:
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0.35.0
with:
scan-type: 'fs'
ignore-unfixed: true
format: 'sarif'
output: 'trivy-results.sarif'
- run: |
jq '.runs[].tool.driver.name = "trivy-fs"' < trivy-results.sarif > tmp
mv tmp trivy-results.sarif
- uses: github/codeql-action/upload-sarif@1b549b9259bda1cb5ddde3b41741a82a2d15a841 # v3.28.13
with:
sarif_file: 'trivy-results.sarif'
category: trivy-fs