File tree 2 files changed +8
-2
lines changed
2 files changed +8
-2
lines changed Original file line number Diff line number Diff line change @@ -46,13 +46,16 @@ jobs:
46
46
- name : Push images
47
47
run : ./build --push
48
48
- name : Run Trivy vulnerability scanner
49
- uses : aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # v0.24 .0
49
+ uses : aquasecurity/trivy-action@915b19bbe73b92a6cf82a1bc12b087c9a19a5fe2 # v0.28 .0
50
50
with :
51
51
image-ref : ' ${{ steps.build.outputs.LATEST_IMAGE_TAG }}'
52
52
format : ' sarif'
53
53
output : ' trivy-results.sarif'
54
54
severity : ' CRITICAL,HIGH'
55
55
limit-severities-for-sarif : true
56
+ env :
57
+ TRIVY_DB_REPOSITORY : ghcr.io/aquasecurity/trivy-db,public.ecr.aws/aquasecurity/trivy-db
58
+ TRIVY_JAVA_DB_REPOSITORY : ghcr.io/aquasecurity/trivy-java-db,public.ecr.aws/aquasecurity/trivy-java-db
56
59
- name : Upload Trivy scan results to GitHub Security tab
57
60
uses : github/codeql-action/upload-sarif@v3
58
61
with :
Original file line number Diff line number Diff line change @@ -30,13 +30,16 @@ jobs:
30
30
docker-images : false # Do not remove locally built images (including trivy scanner)
31
31
32
32
- name : Run Trivy vulnerability scanner
33
- uses : aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # v0.24 .0
33
+ uses : aquasecurity/trivy-action@915b19bbe73b92a6cf82a1bc12b087c9a19a5fe2 # v0.28 .0
34
34
with :
35
35
image-ref : ' ghcr.io/datadog/dd-trace-java-docker-build:latest'
36
36
format : ' sarif'
37
37
output : ' trivy-results.sarif'
38
38
severity : ' CRITICAL,HIGH'
39
39
limit-severities-for-sarif : true
40
+ env :
41
+ TRIVY_DB_REPOSITORY : ghcr.io/aquasecurity/trivy-db,public.ecr.aws/aquasecurity/trivy-db
42
+ TRIVY_JAVA_DB_REPOSITORY : ghcr.io/aquasecurity/trivy-java-db,public.ecr.aws/aquasecurity/trivy-java-db
40
43
41
44
- name : Upload Trivy scan results to GitHub Security tab
42
45
uses : github/codeql-action/upload-sarif@v3
You can’t perform that action at this time.
0 commit comments