From f2257cfc376213b0a63c41972836c105183b476a Mon Sep 17 00:00:00 2001 From: tzurielw Date: Wed, 20 Sep 2023 17:04:14 +0300 Subject: [PATCH] change nonroot to limited --- .github/workflows/pr-merged.yml | 16 ++++++++-------- README-dockerhub.md | 10 +++++----- 2 files changed, 13 insertions(+), 13 deletions(-) diff --git a/.github/workflows/pr-merged.yml b/.github/workflows/pr-merged.yml index 062971a6..dba62db5 100644 --- a/.github/workflows/pr-merged.yml +++ b/.github/workflows/pr-merged.yml @@ -35,21 +35,21 @@ jobs: docker tag aquasec/aqua-scanner:${{ env.new_version }}-arm64 aquasec/aqua-scanner:latest-arm64 docker push aquasec/aqua-scanner:latest-arm64 - docker pull aquasec/aqua-scanner:${{ env.new_version }}-amd64-nonroot - docker tag aquasec/aqua-scanner:${{ env.new_version }}-amd64-nonroot aquasec/aqua-scanner:latest-amd64-nonroot - docker push aquasec/aqua-scanner:latest-amd64-nonroot + docker pull aquasec/aqua-scanner:${{ env.new_version }}-amd64-limited + docker tag aquasec/aqua-scanner:${{ env.new_version }}-amd64-limited aquasec/aqua-scanner:latest-amd64-limited + docker push aquasec/aqua-scanner:latest-amd64-limited - docker pull aquasec/aqua-scanner:${{ env.new_version }}-arm64-nonroot - docker tag aquasec/aqua-scanner:${{ env.new_version }}-arm64-nonroot aquasec/aqua-scanner:latest-arm64-nonroot - docker push aquasec/aqua-scanner:latest-arm64-nonroot + docker pull aquasec/aqua-scanner:${{ env.new_version }}-arm64-limited + docker tag aquasec/aqua-scanner:${{ env.new_version }}-arm64-limited aquasec/aqua-scanner:latest-arm64-limited + docker push aquasec/aqua-scanner:latest-arm64-limited docker manifest create aquasec/aqua-scanner:latest aquasec/aqua-scanner:latest-amd64 aquasec/aqua-scanner:latest-arm64 docker manifest push aquasec/aqua-scanner:latest - docker manifest create aquasec/aqua-scanner:latest-nonroot aquasec/aqua-scanner:latest-amd64-nonroot aquasec/aqua-scanner:latest-arm64-nonroot - docker manifest push aquasec/aqua-scanner:latest-nonroot + docker manifest create aquasec/aqua-scanner:latest-limited aquasec/aqua-scanner:latest-amd64-limited aquasec/aqua-scanner:latest-arm64-limited + docker manifest push aquasec/aqua-scanner:latest-limited - name: DockerHub description update uses: peter-evans/dockerhub-description@v3 with: diff --git a/README-dockerhub.md b/README-dockerhub.md index 3136c9a0..e6c0b86f 100644 --- a/README-dockerhub.md +++ b/README-dockerhub.md @@ -145,13 +145,13 @@ podman run --rm \ When working within CI environment, it's important to include the Source Code Management (SCM) tokens for pull requests. You can find additional guidance and details on this matter within our platform for your reference about each SCM. -# aqua-scanner nonroot Tag +# aqua-scanner limited Tag -We provide a dedicated nonroot tag, for running the aqua-scanner on a nonroot user. +We provide a dedicated limited tag, for running the aqua-scanner on a limited user. -## Running nonroot tag on Azure DevOps pipeline +## Running limited tag on Azure DevOps pipeline -To use this tag effectively in Azure DevOps Pipelines, follow the steps below ([Azure documentation](This README provides guidance on how to use the Docker Hub nonroot User Tag in Azure DevOps Pipelines to run containers with reduced privileges.)). +To use this tag effectively in Azure DevOps Pipelines, follow the steps below ([Azure documentation](This README provides guidance on how to use the Docker Hub limited User Tag in Azure DevOps Pipelines to run containers with reduced privileges.)). ## Add user 0 option to the container options ```shell @@ -159,7 +159,7 @@ trigger: - main container: - image: aquasec/aqua-scanner:nonroot + image: aquasec/aqua-scanner:limited options: -u 0 env: AQUA_KEY: $(AQUA_KEY)