Skip to content

Commit 8dc28ce

Browse files
committed
Revert "(maint) Temporarily disable trivy scans due to rate limiting"
This reverts commit 3cd32d8.
1 parent 948cf7c commit 8dc28ce

File tree

3 files changed

+30
-0
lines changed

3 files changed

+30
-0
lines changed

.github/workflows/build-test-push.yml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,16 @@ jobs:
1919
run: ./build-rootless.sh $(echo $GITHUB_REPOSITORY |cut -d '/' -f1)
2020
- name: Build standard image
2121
run: ./build.sh $(echo $GITHUB_REPOSITORY |cut -d '/' -f1)
22+
- name: Trivy scan
23+
uses: aquasecurity/trivy-action@master
24+
with:
25+
image-ref: puppet-dev-tools:latest
26+
exit-code: 1
27+
ignore-unfixed: true
28+
severity: 'CRITICAL,HIGH,MEDIUM'
29+
vuln-type: os
30+
timeout: 10m0s
31+
skip-files: "/root/.pdk/cache/ruby/*/gems/aws-sdk-core-*/lib/aws-sdk-ssooidc/client.rb"
2232
- name: Run tests
2333
run: cd tests; ./run_tests.sh
2434
- name: Tag Docker images

.github/workflows/build-test.yml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,16 @@ jobs:
1818
- name: Show Docker image labels
1919
run: |
2020
docker inspect --format='{{json .Config.Labels}}' ${{ secrets.DOCKERHUB_USERNAME }}/puppet-dev-tools
21+
- name: Trivy scan
22+
uses: aquasecurity/trivy-action@master
23+
with:
24+
image-ref: puppet-dev-tools:latest
25+
exit-code: 1
26+
ignore-unfixed: true
27+
severity: 'CRITICAL,HIGH,MEDIUM'
28+
vuln-type: os
29+
timeout: 10m0s
30+
skip-files: "/root/.pdk/cache/ruby/*/gems/aws-sdk-core-*/lib/aws-sdk-ssooidc/client.rb"
2131
- name: Run tests
2232
working-directory: ${{ github.workspace }}/tests
2333
run: ./run_tests.sh

.github/workflows/publish-4x-image.yml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,16 @@ jobs:
2323
IMAGE_TAG: ${{ github.event.inputs.image_tag }}
2424
run: |
2525
docker pull ${IMAGE_BASE}:${IMAGE_TAG}
26+
- name: Trivy scan
27+
uses: aquasecurity/trivy-action@master
28+
with:
29+
image-ref: ${{ env.IMAGE_BASE }}:${{ github.event.inputs.image_tag }}
30+
exit-code: 1
31+
ignore-unfixed: true
32+
severity: 'CRITICAL,HIGH,MEDIUM'
33+
vuln-type: os
34+
timeout: 10m0s
35+
skip-files: "/root/.pdk/cache/ruby/*/gems/aws-sdk-core-*/lib/aws-sdk-ssooidc/client.rb"
2636
- name: Publish standard image to 4.x
2737
env:
2838
IMAGE_TAG: ${{ github.event.inputs.image_tag }}

0 commit comments

Comments
 (0)