Skip to content

Commit

Permalink
chore: scan images for vulnerabilities (#907)
Browse files Browse the repository at this point in the history
"Drink our own Aqua"

Signed-off-by: Daniel Pacak <pacak.daniel@gmail.com>
  • Loading branch information
danielpacak committed Jan 19, 2022
1 parent a65a584 commit 6294d9e
Showing 1 changed file with 21 additions and 0 deletions.
21 changes: 21 additions & 0 deletions .github/workflows/build.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -272,3 +272,24 @@ jobs:
with:
version: v1.1.0
args: release --snapshot --skip-publish --rm-dist
- name: Scan Starboard CLI image for vulnerabilities
uses: aquasecurity/trivy-action@master
with:
image-ref: 'docker.io/aquasec/starboard:${{ github.sha }}'
exit-code: '1'
ignore-unfixed: true
severity: 'CRITICAL,HIGH'
- name: Scan Starboard Operator image for vulnerabilities
uses: aquasecurity/trivy-action@master
with:
image-ref: 'docker.io/aquasec/starboard-operator:${{ github.sha }}'
exit-code: '1'
ignore-unfixed: true
severity: 'CRITICAL,HIGH'
- name: Scan Starboard Scanner Aqua image for vulnerabilities
uses: aquasecurity/trivy-action@master
with:
image-ref: 'docker.io/aquasec/starboard-scanner-aqua:${{ github.sha }}'
exit-code: '1'
ignore-unfixed: true
severity: 'CRITICAL,HIGH'

0 comments on commit 6294d9e

Please sign in to comment.