From d102ec6be4929a9fd25cfdabc234cd80472eb5b4 Mon Sep 17 00:00:00 2001 From: Dave Sargent Date: Tue, 29 Oct 2024 15:39:13 -0700 Subject: [PATCH] Switch to env vars for registry and image in trivy --- .github/workflows/trivy.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/trivy.yml b/.github/workflows/trivy.yml index 989e7c1..164cafd 100644 --- a/.github/workflows/trivy.yml +++ b/.github/workflows/trivy.yml @@ -49,12 +49,12 @@ jobs: uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0 with: push: false - tags: ghcr.io/sarg3nt/go-docker-container:${{ github.sha }} + tags: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }} - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@915b19bbe73b92a6cf82a1bc12b087c9a19a5fe2 with: - image-ref: 'ghcr.io/sarg3nt/go-docker-container:${{ github.sha }}' + image-ref: '${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }}' format: 'template' template: '@/contrib/sarif.tpl' output: 'trivy-results.sarif'