From ffe6da53c2a9e4f1464ec81995e478539c700669 Mon Sep 17 00:00:00 2001 From: Xi Xu Date: Tue, 19 Aug 2025 21:21:45 +0800 Subject: [PATCH] Update Trivy scan to use tag instead of digest Added debug output steps and changed the Trivy vulnerability scanner to reference the image by tag (${github.ref_name}) instead of digest. This helps with debugging and aligns the scan with the tagged image. --- .github/workflows/docker.yml | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 119d8f8..d7e6770 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -86,10 +86,17 @@ jobs: security-events: write steps: + - name: Debug outputs + run: | + echo "Image tags: ${{ needs.build-and-push.outputs.image-tags }}" + echo "Image digest: ${{ needs.build-and-push.outputs.image-digest }}" + echo "Registry: ${{ env.REGISTRY }}" + echo "Image name: ${{ env.IMAGE_NAME }}" + - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@master with: - image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}@${{ needs.build-and-push.outputs.image-digest }} + image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.ref_name }} format: 'sarif' output: 'trivy-results.sarif'