Skip to content

Commit 36265dd

Browse files
authored
Merge pull request #3368 from cdr/jsjoeio/re-enable-trivy
fix(ci): re-enable trivy-scan-repo
2 parents f5b7927 + 5fe76bd commit 36265dd

File tree

2 files changed

+5
-8
lines changed

2 files changed

+5
-8
lines changed

.github/workflows/ci.yaml

+4-8
Original file line numberDiff line numberDiff line change
@@ -446,8 +446,8 @@ jobs:
446446
path: ./release-images
447447

448448
- name: Run Trivy vulnerability scanner in image mode
449-
# Commit SHA for v0.0.14
450-
uses: aquasecurity/trivy-action@341f810bd602419f966a081da3f4debedc3e5c8e
449+
# Commit SHA for v0.0.17
450+
uses: aquasecurity/trivy-action@dba83feec810c70bacbc4bead308ae1e466c572b
451451
with:
452452
input: "./release-images/code-server-amd64-*.tar"
453453
scan-type: "image"
@@ -466,16 +466,12 @@ jobs:
466466
# codeql/upload-sarif action per job
467467
trivy-scan-repo:
468468
runs-on: ubuntu-20.04
469-
# NOTE@jsjoeio 5/10/2021
470-
# Disabling until fixed upstream
471-
# See: https://github.com/aquasecurity/trivy-action/issues/22#issuecomment-833768084
472-
if: "1 == 2"
473469
steps:
474470
- name: Checkout code
475471
uses: actions/checkout@v2
476472
- name: Run Trivy vulnerability scanner in repo mode
477-
#Commit SHA for v0.0.14
478-
uses: aquasecurity/trivy-action@341f810bd602419f966a081da3f4debedc3e5c8e
473+
#Commit SHA for v0.0.17
474+
uses: aquasecurity/trivy-action@dba83feec810c70bacbc4bead308ae1e466c572b
479475
with:
480476
scan-type: "fs"
481477
scan-ref: "."

CHANGELOG.md

+1
Original file line numberDiff line numberDiff line change
@@ -75,6 +75,7 @@ VS Code v1.56
7575

7676
- chore: ignore updates to microsoft/playwright-github-action
7777
- fix(socket): use xdgBasedir.runtime instead of tmp #3304 @jsjoeio
78+
- fix(ci): re-enable trivy-scan-repo #3368 @jsjoeio
7879

7980
## 3.10.0
8081

0 commit comments

Comments
 (0)