From a800fd9082952fdc98fdd01671721f28b6ec3134 Mon Sep 17 00:00:00 2001 From: Xi Xu Date: Tue, 19 Aug 2025 21:25:23 +0800 Subject: [PATCH] Fix Trivy scan to use correct image tag Introduced a step to extract the first image tag from build outputs and use it as the image reference for the Trivy vulnerability scanner. This ensures the scanner analyzes the correct image version. --- .github/workflows/docker.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index d7e6770..4546f18 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -93,10 +93,16 @@ jobs: echo "Registry: ${{ env.REGISTRY }}" echo "Image name: ${{ env.IMAGE_NAME }}" + - name: Set image for scanning + id: scan-image + run: | + FIRST_TAG=$(echo "${{ needs.build-and-push.outputs.image-tags }}" | head -n1) + echo "image-ref=${FIRST_TAG}" >> $GITHUB_OUTPUT + - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@master with: - image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.ref_name }} + image-ref: ${{ steps.scan-image.outputs.image-ref }} format: 'sarif' output: 'trivy-results.sarif'