From 8c969b6bbfecbac8b9f231c82a00c334e6e17d33 Mon Sep 17 00:00:00 2001 From: Xi Xu Date: Tue, 19 Aug 2025 21:11:16 +0800 Subject: [PATCH] Update Docker workflow to use image digest for Trivy scan Adds outputs for image tags and digest in the build-and-push job and updates the Trivy scanner to reference the image by digest instead of the latest tag. This ensures the vulnerability scan is performed on the exact built image. --- .github/workflows/docker.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 4daf097..119d8f8 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -19,6 +19,9 @@ env: jobs: build-and-push: runs-on: ubuntu-latest + outputs: + image-tags: ${{ steps.meta.outputs.tags }} + image-digest: ${{ steps.build-and-push.outputs.digest }} permissions: contents: read packages: write @@ -86,7 +89,7 @@ jobs: - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@master with: - image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest + image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}@${{ needs.build-and-push.outputs.image-digest }} format: 'sarif' output: 'trivy-results.sarif'