Browse Source

ci: update trivy scan job

Signed-off-by: Mark Sagi-Kazar <mark.sagikazar@gmail.com>
pull/2473/head
Mark Sagi-Kazar 4 years ago
parent
commit
95e81a925f
No known key found for this signature in database
GPG Key ID: 31AB0439F4C5C90E
  1. 5
      .github/workflows/artifacts.yaml

5
.github/workflows/artifacts.yaml

@ -106,11 +106,10 @@ jobs:
steps:
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@0.2.3
uses: aquasecurity/trivy-action@0.2.4
with:
image-ref: "ghcr.io/dexidp/dex:${{ needs.container-images.outputs.version }}"
format: "template"
template: "@/contrib/sarif.tpl"
format: "sarif"
output: "trivy-results.sarif"
- name: Upload Trivy scan results to GitHub Security tab

Loading…
Cancel
Save