Update Docker workflow to use image digest for Trivy scan

Adds outputs for image tags and digest in the build-and-push job and updates the Trivy scanner to reference the image by digest instead of the latest tag. This ensures the vulnerability scan is performed on the exact built image.
This commit is contained in:
xixu-me committed 2025-08-19 21:11:16 +08:00
1 parent 4fc2cc8002
commit 28b23f31bd
1 file changed
+4 -1
+4 -1
View File
@@ -19,6 +19,9 @@ env:
jobs:
build-and-push:
runs-on: ubuntu-latest
outputs:
image-tags: ${{ steps.meta.outputs.tags }}
image-digest: ${{ steps.build-and-push.outputs.digest }}
permissions:
contents: read
packages: write
@@ -86,7 +89,7 @@ jobs:
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master
with:
image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest
image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}@${{ needs.build-and-push.outputs.image-digest }}
format: 'sarif'
output: 'trivy-results.sarif'