diff --git a/.github/workflows/checkov.yaml b/.github/workflows/checkov.yaml index cfc0e78..58c8a2e 100644 --- a/.github/workflows/checkov.yaml +++ b/.github/workflows/checkov.yaml @@ -22,9 +22,7 @@ jobs: security-events: write runs-on: ubuntu-latest steps: - - uses: actions/checkout@v3 - - name: Build the image - run: docker build -t ${{ env.IMAGE_NAME }} ${{ env.IMAGE_PATH }} + - uses: actions/checkout@v3 - name: Run Checkov action id: checkov uses: bridgecrewio/checkov-action@master diff --git a/.github/workflows/docker-scans.yaml b/.github/workflows/docker-scans.yaml index fc47089..9e74b5f 100644 --- a/.github/workflows/docker-scans.yaml +++ b/.github/workflows/docker-scans.yaml @@ -23,7 +23,7 @@ jobs: contents: read security-events: write uses: 0GiS0/scan-docker-vulnerabilities/.github/workflows/trivy.yaml@main - terrascan: + grype: permissions: contents: read security-events: write diff --git a/.github/workflows/grype.yaml b/.github/workflows/grype.yaml index 8102f17..68c427f 100644 --- a/.github/workflows/grype.yaml +++ b/.github/workflows/grype.yaml @@ -28,6 +28,7 @@ jobs: - name: Build the Container image run: docker build . --file ${{ inputs.dockerfile_path }} --tag ${{ inputs.image_name }} - uses: anchore/scan-action@v3 + continue-on-error: true id: scan with: image: ${{ inputs.image_name }} diff --git a/.github/workflows/trivy.yaml b/.github/workflows/trivy.yaml index fa78051..3ded29c 100644 --- a/.github/workflows/trivy.yaml +++ b/.github/workflows/trivy.yaml @@ -28,7 +28,7 @@ jobs: - name: Build an image from Dockerfile run: | - docker build -t ${{ inputs.image_name }} ${{ inputs.dockerfile_path }} . + docker build -t ${{ inputs.image_name }} -f ${{ inputs.dockerfile_path }} . - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@master