Update Docker workflow to use image digest for Trivy scan
Adds outputs for image tags and digest in the build-and-push job and updates the Trivy scanner to reference the image by digest instead of the latest tag. This ensures the vulnerability scan is performed on the exact built image.
This commit is contained in:
1 parent
4fc2cc8002
commit
28b23f31bd
1 file changed
+4
-1
@@ -19,6 +19,9 @@ env:
|
||||
jobs:
|
||||
build-and-push:
|
||||
runs-on: ubuntu-latest
|
||||
outputs:
|
||||
image-tags: ${{ steps.meta.outputs.tags }}
|
||||
image-digest: ${{ steps.build-and-push.outputs.digest }}
|
||||
permissions:
|
||||
contents: read
|
||||
packages: write
|
||||
@@ -86,7 +89,7 @@ jobs:
|
||||
- name: Run Trivy vulnerability scanner
|
||||
uses: aquasecurity/trivy-action@master
|
||||
with:
|
||||
image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest
|
||||
image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}@${{ needs.build-and-push.outputs.image-digest }}
|
||||
format: 'sarif'
|
||||
output: 'trivy-results.sarif'
|
||||
|
||||
|
||||
Reference in new issue
Block a user