File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 4848 - name : Push images
4949 run : ./build --push
5050 - name : Run Trivy vulnerability scanner
51- uses : aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # v0.33.1
51+ uses : aquasecurity/trivy-action@c1824fd6edce30d7ab345a9989de00bbd46ef284 # v0.34.0
5252 with :
5353 image-ref : ' ${{ steps.build.outputs.LATEST_IMAGE_TAG }}'
5454 format : ' sarif'
5959 TRIVY_DB_REPOSITORY : ghcr.io/aquasecurity/trivy-db,public.ecr.aws/aquasecurity/trivy-db
6060 TRIVY_JAVA_DB_REPOSITORY : ghcr.io/aquasecurity/trivy-java-db,public.ecr.aws/aquasecurity/trivy-java-db
6161 - name : Upload Trivy scan results to GitHub Security tab
62- uses : github/codeql-action/upload-sarif@6bc82e05fd0ea64601dd4b465378bbcf57de0314 # v4.32.1
62+ uses : github/codeql-action/upload-sarif@9e907b5e64f6b83e7804b09294d44122997950d6 # v4.32.3
6363 with :
6464 sarif_file : ' trivy-results.sarif'
Original file line number Diff line number Diff line change 3030 docker-images : false # Do not remove locally built images (including trivy scanner)
3131
3232 - name : Run Trivy vulnerability scanner
33- uses : aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # v0.33.1
33+ uses : aquasecurity/trivy-action@c1824fd6edce30d7ab345a9989de00bbd46ef284 # v0.34.0
3434 with :
3535 image-ref : ' ghcr.io/datadog/dd-trace-java-docker-build:latest'
3636 format : ' sarif'
4242 TRIVY_JAVA_DB_REPOSITORY : ghcr.io/aquasecurity/trivy-java-db,public.ecr.aws/aquasecurity/trivy-java-db
4343
4444 - name : Upload Trivy scan results to GitHub Security tab
45- uses : github/codeql-action/upload-sarif@6bc82e05fd0ea64601dd4b465378bbcf57de0314 # v4.32.1
45+ uses : github/codeql-action/upload-sarif@9e907b5e64f6b83e7804b09294d44122997950d6 # v4.32.3
4646 if : always()
4747 with :
4848 sarif_file : ' trivy-results.sarif'
You can’t perform that action at this time.
0 commit comments