We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent e618234 commit 4ba9304Copy full SHA for 4ba9304
1 file changed
.github/workflows/security-checks.yml
@@ -8,22 +8,22 @@ on:
8
permissions:
9
contents: read
10
jobs:
11
- trivy:
12
- name: Trivy
+ grype:
+ name: Grype
13
runs-on: ubuntu-latest
14
steps:
15
- name: Checkout Repository
16
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
17
18
- name: Scan repo
19
- uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # 0.35.0
+ uses: anchore/scan-action@7037fa011853d5a11690026fb85feee79f4c946c # v7.3.2
20
+ id: grype-scan
21
with:
- scan-type: 'fs'
22
- scan-ref: '.'
23
- scanners: 'vuln,secret,config'
24
- exit-code: '1'
25
- ignore-unfixed: 'true'
26
- severity: 'MEDIUM,HIGH,CRITICAL'
+ path: "."
+ fail-build: true
+ only-fixed: true
+ severity-cutoff: "medium"
+ output-format: "table"
27
28
npm-audit:
29
name: PNPM Audit
0 commit comments