From 1a71e2e4273d0ee580dd4f86a7a8538303e3a90b Mon Sep 17 00:00:00 2001 From: MohamedSabthar Date: Fri, 1 Nov 2024 10:13:31 +0530 Subject: [PATCH 1/2] Update trivy scan template to use latest version --- .github/workflows/trivy-scan-template.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/trivy-scan-template.yml b/.github/workflows/trivy-scan-template.yml index d849fc39..65a900a5 100644 --- a/.github/workflows/trivy-scan-template.yml +++ b/.github/workflows/trivy-scan-template.yml @@ -43,10 +43,10 @@ jobs: run: mkdir -p ballerina/lib - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@0.23.0 + uses: aquasecurity/trivy-action@master with: scan-type: "rootfs" - scan-ref: "/github/workspace/ballerina/lib" + scan-ref: "${{ github.workspace }}/ballerina/lib" format: "table" timeout: "10m0s" exit-code: "1" From 8b1087df1acf653b0a8fd2de41b2ec2824c53748 Mon Sep 17 00:00:00 2001 From: MohamedSabthar Date: Fri, 1 Nov 2024 10:24:22 +0530 Subject: [PATCH 2/2] Address review suggestions Co-authored-by: Danesh Kuruppu --- .github/workflows/trivy-scan-template.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/trivy-scan-template.yml b/.github/workflows/trivy-scan-template.yml index 65a900a5..1398c5f6 100644 --- a/.github/workflows/trivy-scan-template.yml +++ b/.github/workflows/trivy-scan-template.yml @@ -50,3 +50,4 @@ jobs: format: "table" timeout: "10m0s" exit-code: "1" + scanners: "vuln"