From 6d09497abbd773f26513e3c21f0704e4c437534a Mon Sep 17 00:00:00 2001 From: Dave Sargent Date: Tue, 29 Oct 2024 15:20:41 -0700 Subject: [PATCH] Fix trivy missing repo in tag during image build. --- .github/workflows/trivy.yml | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) diff --git a/.github/workflows/trivy.yml b/.github/workflows/trivy.yml index 6090823..a70cce2 100644 --- a/.github/workflows/trivy.yml +++ b/.github/workflows/trivy.yml @@ -30,8 +30,8 @@ jobs: name: Build runs-on: "ubuntu-20.04" steps: - # - name: Authenticate to GitHub Container Registry - # run: echo "${{ secrets.GITHUB_TOKEN }}" | docker login ghcr.io -u ${{ github.actor }} --password-stdin + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 - name: Log into registry uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0 @@ -45,15 +45,14 @@ jobs: with: egress-policy: audit - - name: Checkout code - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + # - name: Checkout code + # uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - name: Build and push Docker image uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0 with: - context: . push: false - tags: ${{ github.sha }} + tags: ghcr.io/sarg3nt/go-docker-container:${{ github.sha }} - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@915b19bbe73b92a6cf82a1bc12b087c9a19a5fe2