We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent c13afa8 commit 7013bc0Copy full SHA for 7013bc0
1 file changed
.github/workflows/docker-security-scan.yml
@@ -50,7 +50,6 @@ jobs:
50
format: "table"
51
severity: "HIGH,CRITICAL"
52
exit-code: "0" # Don't fail here, just display
53
- scanners: "vuln" # Only vulnerabilities, skip secrets (test containers have legitimate SSH keys)
54
55
- name: Run Trivy vulnerability scanner
56
uses: aquasecurity/trivy-action@0.28.0
@@ -99,6 +98,7 @@ jobs:
99
98
output: "trivy-results.sarif"
100
101
exit-code: "1"
+ scanners: "vuln" # Focus on CVEs, not secrets
102
103
- name: Upload Trivy results to GitHub Security
104
uses: github/codeql-action/upload-sarif@v4
0 commit comments