From 9c27d2c6d1e1d96b91e2c5e482a3e45af55edee7 Mon Sep 17 00:00:00 2001 From: Irtaza Akram Date: Mon, 11 Nov 2024 11:19:22 +0500 Subject: [PATCH] fix: trivy action failure --- .github/workflows/trivy-code-scanning.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/trivy-code-scanning.yml b/.github/workflows/trivy-code-scanning.yml index 72abad83..efaa3d61 100644 --- a/.github/workflows/trivy-code-scanning.yml +++ b/.github/workflows/trivy-code-scanning.yml @@ -19,11 +19,14 @@ jobs: - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@master + env: + # https://github.com/aquasecurity/trivy/discussions/7668#discussioncomment-11141034 + TRIVY_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-db,aquasec/trivy-db,ghcr.io/aquasecurity/trivy-db + TRIVY_JAVA_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-java-db,aquasec/trivy-java-db,ghcr.io/aquasecurity/trivy-java-db with: scan-type: "fs" format: "sarif" output: "trivy-results.sarif" - args: --skip-update - name: Upload Trivy scan results to GitHub Security tab uses: github/codeql-action/upload-sarif@v3