We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 14b0b89 commit 77a02d8Copy full SHA for 77a02d8
.github/workflows/build.yml
@@ -88,6 +88,22 @@ jobs:
88
labels: ${{ steps.meta.outputs.labels }}
89
file: ${{ matrix.dockerfile }}
90
91
+ - uses: hands-lab/dockle-action@v1
92
+ with:
93
+ image: ${{ fromJSON(steps.meta.outputs.json).tags[0] }}
94
+
95
+ - name: Trivy Vulnerability Scanner
96
+ uses: aquasecurity/trivy-action@master
97
98
+ image-ref: ${{ fromJSON(steps.meta.outputs.json).tags[0] }}
99
+ format: 'sarif'
100
+ output: 'trivy-results.sarif'
101
102
+ - name: Upload Trivy scan results to GitHub Security tab
103
+ uses: github/codeql-action/upload-sarif@v2
104
105
+ sarif_file: 'trivy-results.sarif'
106
107
- name: Scan Image with Azure Container Scan
108
uses: Azure/container-scan@v0.1
109
if: always()
0 commit comments