ci: update trivy scan job

Signed-off-by: Mark Sagi-Kazar <mark.sagikazar@gmail.com>
This commit is contained in:
Mark Sagi-Kazar 2022-04-14 15:08:26 +02:00
parent 4a5f2dbb4d
commit 95e81a925f
No known key found for this signature in database
GPG key ID: 31AB0439F4C5C90E

View file

@ -106,11 +106,10 @@ jobs:
steps: steps:
- name: Run Trivy vulnerability scanner - name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@0.2.3 uses: aquasecurity/trivy-action@0.2.4
with: with:
image-ref: "ghcr.io/dexidp/dex:${{ needs.container-images.outputs.version }}" image-ref: "ghcr.io/dexidp/dex:${{ needs.container-images.outputs.version }}"
format: "template" format: "sarif"
template: "@/contrib/sarif.tpl"
output: "trivy-results.sarif" output: "trivy-results.sarif"
- name: Upload Trivy scan results to GitHub Security tab - name: Upload Trivy scan results to GitHub Security tab