Skip to content

Commit e46ad39

Browse files
committed
refactor: download release image and scan .tar
1 parent 6f4de4c commit e46ad39

File tree

1 file changed

+8
-8
lines changed

1 file changed

+8
-8
lines changed

.github/workflows/ci.yaml

+8-8
Original file line numberDiff line numberDiff line change
@@ -409,18 +409,12 @@ jobs:
409409

410410
trivy-scan:
411411
runs-on: ubuntu-20.04
412-
needs: package-linux-amd64
412+
needs: docker-amd64
413413

414414
steps:
415415
- name: Checkout code
416416
uses: actions/checkout@v2
417417

418-
- name: Download release package
419-
uses: actions/download-artifact@v2
420-
with:
421-
name: release-packages
422-
path: ./release-packages
423-
424418
- name: Run Trivy vulnerability scanner in repo mode
425419
uses: aquasecurity/trivy-action@master
426420
with:
@@ -432,10 +426,16 @@ jobs:
432426
output: "trivy-repo-results.sarif"
433427
severity: "CRITICAL"
434428

429+
- name: Download release images
430+
uses: actions/download-artifact@v2
431+
with:
432+
name: release-images
433+
path: ./release-images
434+
435435
- name: Run Trivy vulnerability scanner in image mode
436436
uses: aquasecurity/trivy-action@master
437437
with:
438-
image-ref: "codercom/code-server:${{ github.sha }}"
438+
input: "./release-images/*.tar"
439439
scan-type: "image"
440440
ignore-unfixed: true
441441
format: "template"

0 commit comments

Comments
 (0)