diff --git a/.github/workflows/docker_build.yml b/.github/workflows/docker_build.yml index dbd369cd..333e0dc1 100644 --- a/.github/workflows/docker_build.yml +++ b/.github/workflows/docker_build.yml @@ -54,4 +54,12 @@ jobs: build-args: | DCA_VERSION=${{ env.DCA_VERSION }} + - name: Run Trivy vulnerability scanner + uses: aquasecurity/trivy-action@master + with: + image-ref: '${{ env.IMAGE_PATH }}:${{ env.DCA_VERSION }}' + format: 'table' + exit-code: '1' + ignore-unfixed: true + severity: 'CRITICAL,HIGH'