From 52e43a01ee9ef74a4de1e9e768d7784cdd2b200a Mon Sep 17 00:00:00 2001 From: adityagajbhiye9 <133367448+adityagajbhiye9@users.noreply.github.com> Date: Thu, 11 Jul 2024 11:58:47 +0530 Subject: [PATCH 1/2] Trivy workflow update - trivy workflow update. - dependabot issues fix. --- .github/workflows/dockerbuild.yaml | 2 +- .github/workflows/trivy.yml | 5 +++-- 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/.github/workflows/dockerbuild.yaml b/.github/workflows/dockerbuild.yaml index 2f0e74b93..148d2a6ae 100644 --- a/.github/workflows/dockerbuild.yaml +++ b/.github/workflows/dockerbuild.yaml @@ -80,7 +80,7 @@ jobs: password: ${{ secrets.DOCKER_HUB_TOKEN }} - name: Build and push - uses: docker/build-push-action@v5 + uses: docker/build-push-action@v6 with: context: . file: ./build/Dockerfile diff --git a/.github/workflows/trivy.yml b/.github/workflows/trivy.yml index 403549944..edf1d698d 100644 --- a/.github/workflows/trivy.yml +++ b/.github/workflows/trivy.yml @@ -38,14 +38,15 @@ jobs: steps: - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@0.20.0 + uses: aquasecurity/trivy-action@0.23.0 with: image-ref: "tractusx/managed-simple-data-exchanger-backend:latest" # Pull image from Docker Hub and run Trivy vulnerability scanner format: "sarif" output: "trivy-results.sarif" - exit-code: "1" # Trivy exits with code 1 if vulnerabilities are found, causing the workflow step to fail. severity: "CRITICAL,HIGH" # While vulnerabilities of all severities are reported in the SARIF output, the exit code and workflow failure are triggered only by these specified severities (CRITICAL or HIGH). hide-progress: false + exit-code: "1" # Trivy exits with code 1 if vulnerabilities are found, causing the workflow step to fail. + limit-severities-for-sarif: true - name: Upload Trivy scan results to GitHub Security tab uses: github/codeql-action/upload-sarif@v3 From 4a1d02481dec56eacb1e81feefc019d2958968aa Mon Sep 17 00:00:00 2001 From: adityagajbhiye9 <133367448+adityagajbhiye9@users.noreply.github.com> Date: Fri, 19 Jul 2024 14:01:26 +0530 Subject: [PATCH 2/2] Update trivy.yml - trivy action update as per dependabot. --- .github/workflows/trivy.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/trivy.yml b/.github/workflows/trivy.yml index edf1d698d..a74633c6a 100644 --- a/.github/workflows/trivy.yml +++ b/.github/workflows/trivy.yml @@ -38,7 +38,7 @@ jobs: steps: - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@0.23.0 + uses: aquasecurity/trivy-action@0.24.0 with: image-ref: "tractusx/managed-simple-data-exchanger-backend:latest" # Pull image from Docker Hub and run Trivy vulnerability scanner format: "sarif" @@ -52,4 +52,4 @@ jobs: uses: github/codeql-action/upload-sarif@v3 if: always() with: - sarif_file: "trivy-results.sarif" \ No newline at end of file + sarif_file: "trivy-results.sarif"