From 4069038fecad43b3e1d3695bb44aa23774d399c8 Mon Sep 17 00:00:00 2001 From: Christian Steinle Date: Mon, 3 Mar 2025 15:49:53 +0100 Subject: [PATCH] Tryout trivy vulnerability scanner. --- .gitea/workflows/release.yml | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index 3dbe440..9c8095f 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -38,4 +38,14 @@ jobs: ACTIONS_RUNTIME_TOKEN: '' with: tags: cs-git.ddnss.de/arbeitsschutz-ulm/website:master - push: true \ No newline at end of file + push: true + + - name: Run Trivy vulnerability scanner + uses: aquasecurity/trivy-action@master + with: + image-ref: 'cs-git.ddnss.de/arbeitsschutz-ulm/website:master' + format: 'sarif' + output: 'trivy-results.sarif' + env: + TRIVY_USERNAME: ${{ env.USER }} + TRIVY_PASSWORD: ${{ env.PASS }}