Merge pull request #2487 from kubernetes-sigs/raffo/fix-trivy-again

Fix trivy workflow
This commit is contained in:
Kubernetes Prow Robot 2021-12-20 11:05:33 -08:00 committed by GitHub
commit d3fd0ade88
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 3 additions and 3 deletions

View File

@ -1,8 +1,6 @@
name: trivy vulnerability scanner
on:
push:
branches:
- master
jobs:
build:
name: Build

View File

@ -2,10 +2,12 @@
set -e
# install trivy
cd /tmp
curl -LO https://github.com/aquasecurity/trivy/releases/download/v0.20.2/trivy_0.20.2_Linux-64bit.tar.gz
echo "38a6de48e21a34e0fa0d2cf63439c0afcbbae0e78fb3feada7a84a9cf6e7f60c trivy_0.20.2_Linux-64bit.tar.gz" | sha256sum -c
tar -xvf trivy_0.20.2_Linux-64bit.tar.gz
chmod +x trivy
# run trivy
./trivy image --exit-code 1 us.gcr.io/k8s-artifacts-prod/external-dns/external-dns:$(git describe --tags --always --dirty)
cd -
/tmp/trivy image --exit-code 1 us.gcr.io/k8s-artifacts-prod/external-dns/external-dns:$(git describe --tags --always --dirty)