Update Trivy scan to use tag instead of digest

Added debug output steps and changed the Trivy vulnerability scanner to reference the image by tag (${github.ref_name}) instead of digest. This helps with debugging and aligns the scan with the tagged image.
This commit is contained in:
xixu-me committed 2025-08-19 21:21:45 +08:00
1 parent 8c969b6bbf
commit ffe6da53c2
1 file changed
+8 -1
+8 -1
View File
@@ -86,10 +86,17 @@ jobs:
security-events: write
steps:
- name: Debug outputs
run: |
echo "Image tags: ${{ needs.build-and-push.outputs.image-tags }}"
echo "Image digest: ${{ needs.build-and-push.outputs.image-digest }}"
echo "Registry: ${{ env.REGISTRY }}"
echo "Image name: ${{ env.IMAGE_NAME }}"
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master
with:
image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}@${{ needs.build-and-push.outputs.image-digest }}
image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.ref_name }}
format: 'sarif'
output: 'trivy-results.sarif'