Skip to content

Commit dc6bd88

Browse files
committed
fix: vulnerability scan w/trivy
We should setup the latest go before loading trivy, otherwise an older go version installed on the runner is checked. Also: specified a more up to date trivy version than the default used by the action. Signed-off-by: Frederic BIDON <fredbi@yahoo.com>
1 parent 88b44bd commit dc6bd88

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

.github/workflows/scanner.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,12 @@ jobs:
3030
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
3131
with:
3232
persist-credentials: false
33+
-
34+
uses: actions/setup-go@4dc6199c7b1a012772edbd06daecab0f50c9053c # v6.1.0
35+
with:
36+
go-version: stable
37+
check-latest: true
38+
cache: true
3339
-
3440
name: Vulnerability scan by trivy
3541
uses: aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # v0.33.1
@@ -39,6 +45,7 @@ jobs:
3945
hide-progress: false
4046
output: trivy-code-report.sarif
4147
scanners: vuln,secret
48+
trivy-version: v0.68.0
4249
exit-code: 0
4350
-
4451
name: Upload trivy findings to code scanning dashboard

0 commit comments

Comments
 (0)