Skip to content

Commit

Permalink
Merge pull request #1 from maykinmedia/feature/add-trivy-image-scan
Browse files Browse the repository at this point in the history
👷 [maykinmedia/objects-api#463] Add trivy image scan
  • Loading branch information
stevenbal authored Nov 1, 2024
2 parents 17fe4a0 + 29724c4 commit 0c0c25d
Showing 1 changed file with 29 additions and 0 deletions.
29 changes: 29 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -108,3 +108,32 @@ jobs:
name: docker-image
path: image.tar
retention-days: 1

image_scan:
runs-on: ubuntu-latest
name: Scan docker image
needs:
- docker-build

steps:
# So the scanner gets commit meta-information
- name: Checkout code
uses: actions/checkout@v4

- name: Download built image
uses: actions/download-artifact@v4
with:
name: docker-image

- name: Scan image with Trivy
uses: aquasecurity/trivy-action@master
with:
input: ${{ github.workspace }}/image.tar # from download-artifact
format: 'sarif'
output: 'trivy-results-docker.sarif'
ignore-unfixed: true

- name: Upload results to GH Security tab
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: 'trivy-results-docker.sarif'

0 comments on commit 0c0c25d

Please sign in to comment.