File tree Expand file tree Collapse file tree 2 files changed +27
-1
lines changed Expand file tree Collapse file tree 2 files changed +27
-1
lines changed Original file line number Diff line number Diff line change @@ -157,7 +157,7 @@ jobs:
157
157
with :
158
158
sarif_file : ' snyk.sarif'
159
159
scan :
160
- name : " Trivy"
160
+ name : " Trivy (sarif) "
161
161
runs-on : ubuntu-latest
162
162
needs : build
163
163
permissions :
@@ -187,3 +187,25 @@ jobs:
187
187
uses : github/codeql-action/upload-sarif@v3
188
188
with :
189
189
sarif_file : ' trivy-results.sarif'
190
+
191
+ report :
192
+ name : " Trivy (report)"
193
+ runs-on : ubuntu-latest
194
+ needs : build
195
+ steps :
196
+ - name : Download artifact
197
+ uses : actions/download-artifact@v4
198
+ with :
199
+ name : ${{ env.ARTIFACT_NAME }}_prod
200
+ path : /tmp/
201
+
202
+ - name : Load image
203
+ run : |
204
+ docker load --input /tmp/${{ env.ARTIFACT_NAME }}_prod.tar
205
+ docker image ls -a
206
+
207
+ - name : Run Trivy vulnerability scanner
208
+ uses :
aquasecurity/[email protected]
209
+ with :
210
+ image-ref : ${{ env.IMAGE_NAME }}:${{ github.sha }}
211
+ format : ' table'
Original file line number Diff line number Diff line change @@ -5,6 +5,8 @@ ENV WORKDIR=/app
5
5
WORKDIR ${WORKDIR}
6
6
7
7
RUN apk add --update --no-cache make
8
+ RUN apk upgrade --update --no-cache openssl libcrypto3 libssl3 # FIX CVE-2024-5535
9
+ RUN apk upgrade --update --no-cache --available # FIX CVE-2024-5535 CVE-2024-4741
8
10
9
11
# ##############################################################################
10
12
FROM base AS lint
@@ -92,6 +94,8 @@ CMD ["make", "test"]
92
94
# # WORKDIR and USER are maintained
93
95
# #
94
96
FROM eclipse-temurin:22.0.1_8-jre-alpine AS production
97
+ RUN apk upgrade --update --no-cache openssl libcrypto3 libssl3 # FIX CVE-2024-5535
98
+ RUN apk upgrade --update --no-cache --available # FIX CVE-2024-5535 CVE-2024-4741
95
99
96
100
ENV LOG_LEVEL=INFO
97
101
ENV BRUTEFORCE=false
You can’t perform that action at this time.
0 commit comments