Skip to content

Bump express from 4.18.3 to 4.19.2 #13

Bump express from 4.18.3 to 4.19.2

Bump express from 4.18.3 to 4.19.2 #13

name: Trivy Image Scan on Push/Pull Request
on:
push:
branches: [ main ]
pull_request:
branches: [ main ]
jobs:
trivy_scan:
name: Run Trivy Scan on Terraform Website Image
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v3
- name: Pull Trivy
run: docker pull aquasec/trivy:latest
- name: Scan the Docker image with Trivy and Save Logs
continue-on-error: true
run: |
mkdir -p trivy-reports
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock -v $HOME/.cache:/root/.cache aquasec/trivy:latest image --exit-code 1 --no-progress ghcr.io/theslash84/terraform-website:1.0.0 > trivy-reports/report.txt || true
- name: Upload Trivy scan report
uses: actions/upload-artifact@v2
if: always() # Ensures that the upload step always runs regardless of the previous step's result
with:
name: trivy-report
path: trivy-reports/report.txt