Skip to content

Fix Container workflow Trivy failure from npm's bundled undici #7

Fix Container workflow Trivy failure from npm's bundled undici

Fix Container workflow Trivy failure from npm's bundled undici #7

Workflow file for this run

name: Container
# Builds and pushes a production Docker image to GHCR. Pull and run on your host or PaaS.
# Required repository variables (Settings → Secrets and variables → Actions → Variables):
# VITE_SUPABASE_URL, VITE_SUPABASE_ANON_KEY
# Optional: VITE_ADMIN_EMAILS
#
# Set GHCR package visibility to private after first push (Settings → Packages).
on:
workflow_dispatch:
push:
branches: [main]
paths:
- "Dockerfile"
- "server/**"
- "src/**"
- "package*.json"
- ".github/workflows/deploy.yml"
permissions:
contents: read
packages: write
env:
REGISTRY: ghcr.io
jobs:
build-push:
name: Build and push Docker image
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- name: Set image name
id: image
shell: bash
run: echo "name=${GITHUB_REPOSITORY,,}" >> "$GITHUB_OUTPUT"
- uses: docker/setup-buildx-action@v4
- uses: docker/login-action@v4
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- uses: docker/build-push-action@v7
with:
context: .
push: false
load: true
build-args: |
VITE_SUPABASE_URL=${{ vars.VITE_SUPABASE_URL }}
VITE_SUPABASE_ANON_KEY=${{ vars.VITE_SUPABASE_ANON_KEY }}
VITE_ADMIN_EMAILS=${{ vars.VITE_ADMIN_EMAILS }}
tags: ${{ env.REGISTRY }}/${{ steps.image.outputs.name }}:${{ github.sha }}
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Scan image for vulnerabilities
uses: aquasecurity/trivy-action@v0.36.0
with:
image-ref: ${{ env.REGISTRY }}/${{ steps.image.outputs.name }}:${{ github.sha }}
format: table
severity: CRITICAL,HIGH
exit-code: 1
- name: Push image
run: docker push ${{ env.REGISTRY }}/${{ steps.image.outputs.name }}:${{ github.sha }}