Skip to content

Commit

Permalink
ci: add Trivy fallback DB repositories
Browse files Browse the repository at this point in the history
Just adding these now to try to avoid people hitting the Trivy rate limiting issues later.
  • Loading branch information
adamconnelly committed Oct 22, 2024
1 parent f068a59 commit ef6d008
Showing 1 changed file with 6 additions and 2 deletions.
8 changes: 6 additions & 2 deletions .github/workflows/trivy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,20 +28,24 @@ jobs:
repository_url: "ghcr.io/spacelift-io/vcs-agent"

- name: Run Trivy vulnerability scanner (amd64)
uses: aquasecurity/trivy-action@master
uses: aquasecurity/trivy-action@0.27.0
with:
image-ref: "ghcr.io/spacelift-io/vcs-agent:${{ fromJson(steps.goreleaser.outputs.metadata).version }}-amd64"
format: "sarif"
output: "trivy-results-amd64.sarif"
severity: "CRITICAL,HIGH"
env:
TRIVY_DB_REPOSITORY: ghcr.io/aquasecurity/trivy-db,public.ecr.aws/aquasecurity/trivy-db

- name: Run Trivy vulnerability scanner (arm64)
uses: aquasecurity/trivy-action@master
uses: aquasecurity/trivy-action@0.27.0
with:
image-ref: "ghcr.io/spacelift-io/vcs-agent:${{ fromJson(steps.goreleaser.outputs.metadata).version }}-arm64"
format: "sarif"
output: "trivy-results-arm64.sarif"
severity: "CRITICAL,HIGH"
env:
TRIVY_DB_REPOSITORY: ghcr.io/aquasecurity/trivy-db,public.ecr.aws/aquasecurity/trivy-db

- name: Upload Trivy scan results to GitHub Security tab (amd64)
uses: github/codeql-action/upload-sarif@v3
Expand Down

0 comments on commit ef6d008

Please sign in to comment.