Skip to content

Merge pull request #397 from stefanprodan/dependabot/github_actions/a… #200

Merge pull request #397 from stefanprodan/dependabot/github_actions/a…

Merge pull request #397 from stefanprodan/dependabot/github_actions/a… #200

Workflow file for this run

name: cve-scan
on:
push:
branches:
- "master"
permissions:
contents: read
jobs:
trivy:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Build image
id: build
run: |
IMAGE=test/podinfo:${GITHUB_SHA}
docker build -t ${IMAGE} .
echo "image=$IMAGE" >> $GITHUB_OUTPUT
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@v0.30.0
with:
image-ref: ${{ steps.build.outputs.image }}
format: table
exit-code: "1"
ignore-unfixed: true
vuln-type: os,library
severity: CRITICAL,HIGH