Skip to content

Commit

Permalink
Merge pull request #87 from marinade-finance/trivy-update
Browse files Browse the repository at this point in the history
trivy: update - do not omit report on fail
  • Loading branch information
shejby authored Jan 23, 2025
2 parents aed5e7e + 853a189 commit 1973861
Show file tree
Hide file tree
Showing 2 changed files with 39 additions and 27 deletions.
64 changes: 38 additions & 26 deletions .github/workflows/trivy-scan.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,31 +6,43 @@ jobs:
name: Scan
runs-on: ubuntu-latest
steps:
- name: Checkout project
uses: actions/checkout@v4
- name: Checkout project
uses: actions/checkout@v4

- name: Run Trivy scanner
uses: aquasecurity/trivy-action@master
env:
TRIVY_SKIP_DB_UPDATE: true
TRIVY_SKIP_JAVA_DB_UPDATE: true
with:
scan-type: fs
format: table
scan-ref: .
hide-progress: false
output: trivy.txt
severity: CRITICAL
ignore-unfixed: true
exit-code: 1
- name: Run Trivy scanner - generate update
uses: aquasecurity/trivy-action@master
env:
TRIVY_SKIP_DB_UPDATE: true
TRIVY_SKIP_JAVA_DB_UPDATE: true
with:
scan-type: fs
format: table
scan-ref: .
hide-progress: false
output: trivy.txt

- name: Publish Trivy Output to Summary
run: |
if [[ -s trivy.txt ]]; then
{
echo "### Security Output"
echo '```terraform'
cat trivy.txt
echo '```'
} >> $GITHUB_STEP_SUMMARY
fi
- name: Publish Trivy Output to Summary
run: |
if [[ -s trivy.txt ]]; then
{
echo "### Security Output"
echo '```terraform'
cat trivy.txt
echo '```'
} >> $GITHUB_STEP_SUMMARY
fi
- name: Run Trivy scanner - Fail build on Criticial Vulnerabilities
uses: aquasecurity/trivy-action@master
env:
TRIVY_SKIP_DB_UPDATE: true
TRIVY_SKIP_JAVA_DB_UPDATE: true
with:
scan-type: fs
format: table
scan-ref: .
hide-progress: false
output: trivy.txt
severity: CRITICAL
ignore-unfixed: true
exit-code: 1
2 changes: 1 addition & 1 deletion .github/workflows/trivy-udpate-cache.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ name: Trivy - Cache Update
on:
workflow_dispatch:
schedule:
- cron: '0 0 * * *'
- cron: "0 0 * * *"

jobs:
update-trivy-db:
Expand Down

0 comments on commit 1973861

Please sign in to comment.