File tree Expand file tree Collapse file tree 2 files changed +24
-1
lines changed Expand file tree Collapse file tree 2 files changed +24
-1
lines changed Original file line number Diff line number Diff line change @@ -157,7 +157,7 @@ jobs:
157157 with :
158158 sarif_file : ' snyk.sarif'
159159 scan :
160- name : " Trivy"
160+ name : " Trivy (sarif) "
161161 runs-on : ubuntu-latest
162162 needs : build
163163 permissions :
@@ -187,3 +187,25 @@ jobs:
187187 uses : github/codeql-action/upload-sarif@v3
188188 with :
189189 sarif_file : ' trivy-results.sarif'
190+
191+ report :
192+ name : " Trivy (report)"
193+ runs-on : ubuntu-latest
194+ needs : build
195+ steps :
196+ - name : Download artifact
197+ uses : actions/download-artifact@v4
198+ with :
199+ name : ${{ env.ARTIFACT_NAME }}_prod
200+ path : /tmp/
201+
202+ - name : Load image
203+ run : |
204+ docker load --input /tmp/${{ env.ARTIFACT_NAME }}_prod.tar
205+ docker image ls -a
206+
207+ - name : Run Trivy vulnerability scanner
208+ uses : aquasecurity/trivy-action@0.24.0
209+ with :
210+ image-ref : ${{ env.IMAGE_NAME }}:${{ github.sha }}
211+ format : ' table'
Original file line number Diff line number Diff line change 22FROM node:22.5.1-alpine3.20 AS base
33
44RUN apk add --update --no-cache make
5+ RUN apk upgrade --update --no-cache openssl libcrypto3 libssl3 # FIX CVE-2024-5535
56
67ENV WORKDIR=/app
78WORKDIR ${WORKDIR}
You can’t perform that action at this time.
0 commit comments