Skip to content

Commit ca074b7

Browse files
committed
Ignore pipeline files when scanning with Trivy
Trivy was detecting dependencies inside the Git checkout for Trivy report templates. Also switch to "repository" scanning as it is more appropriate here. See: https://trivy.dev/v0.64/docs/target/repository#rationale
1 parent c97ef3a commit ca074b7

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

.gitlab-ci.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -206,7 +206,7 @@ trivy:
206206
# Trivy needs a populated Go module cache to detect Go module licenses.
207207
- go mod download
208208
- >-
209-
trivy filesystem . --exit-code 1
209+
trivy repository . --exit-code 1 --skip-dirs .gitlab-remotes
210210
--scanners license,vuln
211211
--ignore-unfixed
212212
--no-progress

0 commit comments

Comments
 (0)