Skip to content
Snippets Groups Projects
Commit 9e918f11 authored by Joost Hemmen's avatar Joost Hemmen :basketball:
Browse files

Update file security-scan.gitlab-ci.yml

parent 3134aa46
No related branches found
No related tags found
1 merge request!243Resolve "Document CVEs of images used in docker compose setup"
Pipeline #486445 failed
......@@ -2,8 +2,6 @@
scan-docker-images:
image: "docker:${DOCKER_IMAGE_TAG}"
stage: "scan"
#variables:
# TRIVY_VERSION: "0.58.2" # Current Trivy version
before_script:
# Install Trivy in the pipeline environment
- apk add --no-cache curl
......@@ -11,17 +9,17 @@ scan-docker-images:
script:
- "docker compose pull -q"
- "docker compose build -q"
- for image in $(docker images --format "{{.Repository}}:{{.Tag}}"); do echo "Scanning $image ..."; trivy image $image --severity critical --exit-code 0 >> ./trivy.out; done
artifacts:
when: on_success
paths:
- ./trivy.out
rules:
- if: $CI_COMMIT_BRANCH == "main"
expire_in: 30 days
when: always
- if: $CI_COMMIT_BRANCH != "main"
expire_in: 2 days
when: always
#- for image in $(docker images --format "{{.Repository}}:{{.Tag}}"); do echo "Scanning $image ..."; trivy image $image --severity critical --exit-code 0 >> ./trivy.out; done
#artifacts:
# when: on_success
# paths:
# - ./trivy.out
# rules:
# - if: $CI_COMMIT_BRANCH == "main"
# expire_in: 30 days
# when: always
# - if: $CI_COMMIT_BRANCH != "main"
# expire_in: 2 days
# when: always
tags:
- "dind"
\ No newline at end of file
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment