File tree Expand file tree Collapse file tree 1 file changed +21
-7
lines changed Expand file tree Collapse file tree 1 file changed +21
-7
lines changed Original file line number Diff line number Diff line change 1- name : Trivy
1+ name : Trivy Analysis
22
33permissions :
44 contents : read
99 pull_request :
1010 workflow_dispatch :
1111 push :
12- branches :
13- - master
12+
13+ env :
14+ SARIF_FILE : ' trivy-results.sarif'
15+
1416jobs :
1517 build :
1618 name : Scan
@@ -19,17 +21,29 @@ jobs:
1921 - name : Checkout code
2022 uses : actions/checkout@v4.2.2
2123
22- - name : Run Trivy vulnerability scanner in repo mode
24+ - name : Run Trivy vulnerability scanner on the cloned repository files
2325 uses : aquasecurity/trivy-action@0.30.0
2426 with :
27+ version : ' v0.61.1'
2528 scan-type : ' fs'
26- scanners : ' vuln,misconfig,secret'
29+ scanners : ' vuln,misconfig,secret,license '
2730 ignore-unfixed : true
2831 format : ' sarif'
29- output : ' trivy-results.sarif '
32+ output : ${{ env.SARIF_FILE }}
3033 severity : ' CRITICAL'
3134
35+ - name : Check Trivy scan results existence
36+ run : |
37+ if [ ! -f "${{ env.SARIF_FILE }}" ]; then
38+ echo "Error: ${{ env.SARIF_FILE }} does not exist."
39+ exit 1
40+ fi
41+ ls -lash ${{ env.SARIF_FILE }}
42+
3243 - name : Upload Trivy scan results to GitHub Security tab
3344 uses : github/codeql-action/upload-sarif@v3.28.16
3445 with :
35- sarif_file : ' trivy-results.sarif'
46+ sarif_file : ${{ env.SARIF_FILE }}
47+
48+
49+
You can’t perform that action at this time.
0 commit comments