We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent cdf43f6 commit e4aa042Copy full SHA for e4aa042
.github/workflows/trivy.yml
@@ -16,6 +16,7 @@ on:
16
17
permissions:
18
contents: read
19
+ security-events: write
20
21
jobs:
22
build:
@@ -38,12 +39,11 @@ jobs:
38
39
uses: aquasecurity/trivy-action@18f2510ee396bbf400402947b394f2dd8c87dbb0
40
with:
41
image-ref: '${{ secrets.DOCKER_HUB_USERNAME }}/${{ secrets.DOCKER_HUB_REPOSITORY }}:${{ github.sha }}'
- format: 'template'
42
- template: '@/contrib/sarif.tpl'
+ format: 'sarif'
43
output: 'trivy-results.sarif'
44
severity: 'CRITICAL,HIGH'
45
46
- name: Upload Trivy scan results to GitHub Security tab
47
uses: github/codeql-action/upload-sarif@v3
48
49
- sarif_file: 'trivy-results.sarif'
+ sarif_file: 'trivy-results.sarif'
0 commit comments