Update Trivy scan to use tag instead of digest
Added debug output steps and changed the Trivy vulnerability scanner to reference the image by tag (${github.ref_name}) instead of digest. This helps with debugging and aligns the scan with the tagged image.
This commit is contained in:
1 parent
8c969b6bbf
commit
ffe6da53c2
1 file changed
+8
-1
@@ -86,10 +86,17 @@ jobs:
|
||||
security-events: write
|
||||
|
||||
steps:
|
||||
- name: Debug outputs
|
||||
run: |
|
||||
echo "Image tags: ${{ needs.build-and-push.outputs.image-tags }}"
|
||||
echo "Image digest: ${{ needs.build-and-push.outputs.image-digest }}"
|
||||
echo "Registry: ${{ env.REGISTRY }}"
|
||||
echo "Image name: ${{ env.IMAGE_NAME }}"
|
||||
|
||||
- name: Run Trivy vulnerability scanner
|
||||
uses: aquasecurity/trivy-action@master
|
||||
with:
|
||||
image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}@${{ needs.build-and-push.outputs.image-digest }}
|
||||
image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.ref_name }}
|
||||
format: 'sarif'
|
||||
output: 'trivy-results.sarif'
|
||||
|
||||
|
||||
Reference in new issue
Block a user