Trivy compliant

This commit is contained in:
Samuel Huang
2024-10-03 21:36:40 +10:00
parent a9c25bbf1f
commit 4d3a971d17
2 changed files with 20 additions and 20 deletions

View File

@@ -1,6 +1,7 @@
name: Trivy-scanning name: Trivy-scanning
on: on:
workflow_dispatch:
push: push:
branches: branches:
- master - master
@@ -16,13 +17,12 @@ jobs:
with: with:
ref: ${{ github.ref }} ref: ${{ github.ref }}
- -
name: Run Trivy fs vulnerability scanner name: Run Trivy fs vulnerability scanner in fs mode
uses: aquasecurity/trivy-action@0.20.0 uses: aquasecurity/trivy-action@0.20.0
with: with:
scan-type: 'fs' scan-type: 'fs'
ignore-unfixed: true ignore-unfixed: true
format: 'template' format: 'sarif'
template: '@/contrib/sarif.tpl'
output: 'trivy-results.sarif' output: 'trivy-results.sarif'
#severity: 'CRITICAL' #severity: 'CRITICAL'
- -

View File

@@ -34,30 +34,30 @@ COPY nginx-ws.tpl /etc/nginx/conf.d/
COPY proxy-log-fmt.tpl /etc/nginx/conf.d/000-proxy-log-fmt.conf COPY proxy-log-fmt.tpl /etc/nginx/conf.d/000-proxy-log-fmt.conf
ADD server-lgp.sh /server-lgp.sh COPY server-lgp.sh /server-lgp.sh
ADD server-lgr.sh /server-lgr.sh COPY server-lgr.sh /server-lgr.sh
ADD server-lgt.sh /server-lgt.sh COPY server-lgt.sh /server-lgt.sh
ADD server-lsp.sh /server-lsp.sh COPY server-lsp.sh /server-lsp.sh
ADD server-lst.sh /server-lst.sh COPY server-lst.sh /server-lst.sh
ADD server-ltr.sh /server-ltr.sh COPY server-ltr.sh /server-ltr.sh
ADD server-ltt.sh /server-ltt.sh COPY server-ltt.sh /server-ltt.sh
ADD server-lwp.sh /server-lwp.sh COPY server-lwp.sh /server-lwp.sh
ADD server-lwt.sh /server-lwt.sh COPY server-lwt.sh /server-lwt.sh
ADD server-mtt.sh /server-mtt.sh COPY server-mtt.sh /server-mtt.sh
ADD server-mwp.sh /server-mwp.sh COPY server-mwp.sh /server-mwp.sh
ADD server-mwt.sh /server-mwt.sh COPY server-mwt.sh /server-mwt.sh
ADD server-twp.sh /server-twp.sh COPY server-twp.sh /server-twp.sh
ADD server-ttt.sh /server-ttt.sh COPY server-ttt.sh /server-ttt.sh
ADD server-twt.sh /server-twt.sh COPY server-twt.sh /server-twt.sh
ADD server-nginx.sh /server-nginx.sh COPY server-nginx.sh /server-nginx.sh
ADD run.sh /run.sh COPY run.sh /run.sh
RUN chmod 755 /*.sh RUN chmod 755 /*.sh