From 8431b34fc09d414a35513633e3a2c93214f29ae0 Mon Sep 17 00:00:00 2001 From: Joost Hemmen <joost.hemmen@ufz.de> Date: Tue, 28 Jan 2025 14:47:39 +0100 Subject: [PATCH] Update file security-scan.gitlab-ci.yml --- .gitlab/ci/security-scan.gitlab-ci.yml | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/.gitlab/ci/security-scan.gitlab-ci.yml b/.gitlab/ci/security-scan.gitlab-ci.yml index abd38649..9cd62b6a 100644 --- a/.gitlab/ci/security-scan.gitlab-ci.yml +++ b/.gitlab/ci/security-scan.gitlab-ci.yml @@ -8,18 +8,17 @@ scan-docker-images: # Install Trivy in the pipeline environment - apk add --no-cache curl - curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin v0.58.2 - script: - "docker compose pull -q" - "docker compose build -q" - for image in $(docker images --format "{{.Repository}}:{{.Tag}}"); do echo "Scanning $image ..."; - trivy image $image --severity critical --exit-code 0 >> ./trivy.${image}.out; + trivy image $image --severity critical --exit-code 0 >> ./trivy.out; done artifacts: when: on_success paths: - - trivy-*.json + - ./trivy.out rules: - if: $CI_COMMIT_BRANCH == "main" expire_in: 30 days -- GitLab