Fix Trivy scan to use correct image tag

Introduced a step to extract the first image tag from build outputs and use it as the image reference for the Trivy vulnerability scanner. This ensures the scanner analyzes the correct image version.
This commit is contained in:
xixu-me committed 2025-08-19 21:25:23 +08:00
1 parent 5c9c02008e
commit a800fd9082
1 file changed
+7 -1
+7 -1
View File
@@ -93,10 +93,16 @@ jobs:
echo "Registry: ${{ env.REGISTRY }}"
echo "Image name: ${{ env.IMAGE_NAME }}"
- name: Set image for scanning
id: scan-image
run: |
FIRST_TAG=$(echo "${{ needs.build-and-push.outputs.image-tags }}" | head -n1)
echo "image-ref=${FIRST_TAG}" >> $GITHUB_OUTPUT
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master
with:
image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.ref_name }}
image-ref: ${{ steps.scan-image.outputs.image-ref }}
format: 'sarif'
output: 'trivy-results.sarif'