Skip to content

Commit

Permalink
🤖 Fixup trivy scans (#1093)
Browse files Browse the repository at this point in the history
* 🐧 Delete any files dangling in /tmp

Signed-off-by: mudler <mudler@c3os.io>

* 🤖 Skip /tmp scan in trivy

Signed-off-by: mudler <mudler@c3os.io>

---------

Signed-off-by: mudler <mudler@c3os.io>
  • Loading branch information
mudler authored Mar 10, 2023
1 parent 999e1df commit cc90b66
Showing 1 changed file with 5 additions and 3 deletions.
8 changes: 5 additions & 3 deletions Earthfile
Original file line number Diff line number Diff line change
Expand Up @@ -414,6 +414,8 @@ docker:
END
END

RUN rm -rf /tmp/*

SAVE IMAGE $IMAGE

docker-rootfs:
Expand Down Expand Up @@ -537,9 +539,9 @@ trivy-scan:
ARG FLAVOR
ARG VARIANT
WORKDIR /build
RUN /trivy filesystem --format sarif -o report.sarif --no-progress /
RUN /trivy filesystem --format template --template "@/contrib/html.tpl" -o report.html --no-progress /
RUN /trivy filesystem -f json -o results.json --no-progress /
RUN /trivy filesystem --skip-dirs /tmp --format sarif -o report.sarif --no-progress /
RUN /trivy filesystem --skip-dirs /tmp --format template --template "@/contrib/html.tpl" -o report.html --no-progress /
RUN /trivy filesystem --skip-dirs /tmp -f json -o results.json --no-progress /
SAVE ARTIFACT /build/report.sarif report.sartif AS LOCAL build/${VARIANT}-${FLAVOR}-${VERSION}-trivy.sarif
SAVE ARTIFACT /build/report.html report.html AS LOCAL build/${VARIANT}-${FLAVOR}-${VERSION}-trivy.html
SAVE ARTIFACT /build/results.json results.json AS LOCAL build/${VARIANT}-${FLAVOR}-${VERSION}-trivy.json
Expand Down

0 comments on commit cc90b66

Please sign in to comment.