Skip to content

Commit 417c0f4

Browse files
Remove trivy scanning
1 parent e9524b0 commit 417c0f4

File tree

1 file changed

+0
-30
lines changed

1 file changed

+0
-30
lines changed

.github/workflows/stackhpc-container-image-build.yml

Lines changed: 0 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -250,32 +250,6 @@ jobs:
250250
- name: Fail if no images have been built
251251
run: if [ $(wc -l < ${{ matrix.distro.name }}-${{ matrix.distro.release }}-container-images) -le 1 ]; then exit 1; fi
252252

253-
- name: Scan built container images
254-
run: src/kayobe-config/tools/scan-images.sh ${{ matrix.distro.name }}-${{ matrix.distro.release }} ${{ steps.write-kolla-tag.outputs.kolla-tag }} ${{ inputs.sbom && '--sbom' }}
255-
256-
- name: Move image scan logs to output artifact
257-
run: mv image-scan-output image-build-logs/image-scan-output
258-
259-
- name: Fail if any images have critical vulnerabilities
260-
run: if [ $(wc -l < image-build-logs/image-scan-output/critical-images.txt) -gt 0 ]; then exit 1; fi
261-
if: ${{ !inputs.push-critical }}
262-
263-
- name: Copy clean images to push-attempt-images list
264-
run: cp image-build-logs/image-scan-output/clean-images.txt image-build-logs/push-attempt-images.txt
265-
if: inputs.push
266-
267-
# NOTE(seunghun1ee): This always appends dirty images with CVEs severity lower than critical.
268-
# This should be reverted when it's decided to filter high level CVEs as well.
269-
- name: Append dirty images to push list
270-
run: |
271-
cat image-build-logs/image-scan-output/high-images.txt >> image-build-logs/push-attempt-images.txt
272-
if: ${{ inputs.push }}
273-
274-
- name: Append images with critical vulnerabilities to push list
275-
run: |
276-
cat image-build-logs/image-scan-output/critical-images.txt >> image-build-logs/push-attempt-images.txt
277-
if: ${{ inputs.push && inputs.push-critical }}
278-
279253
- name: Push images
280254
run: |
281255
touch image-build-logs/push-failed-images.txt
@@ -326,10 +300,6 @@ jobs:
326300
# run: if [ $(wc -l < image-build-logs/image-scan-output/high-images.txt) -gt 0 ]; then cat image-build-logs/image-scan-output/high-images.txt && exit 1; fi
327301
# if: ${{ !inputs.push-critical && !cancelled() }}
328302

329-
- name: Fail when critical vulnerabilities are found
330-
run: if [ $(wc -l < image-build-logs/image-scan-output/critical-images.txt) -gt 0 ]; then cat image-build-logs/image-scan-output/critical-images.txt && exit 1; fi
331-
if: ${{ !inputs.push-critical && !cancelled() }}
332-
333303
- name: Remove locally built images for this run
334304
if: always() && runner.arch == 'ARM64'
335305
run: |

0 commit comments

Comments
 (0)