Skip to content

Commit 43fb209

Browse files
committed
ci(gha): add steps to perform container image scan
1 parent 36696b6 commit 43fb209

File tree

1 file changed

+3
-8
lines changed

1 file changed

+3
-8
lines changed

.github/workflows/pipeline.yml

Lines changed: 3 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -224,12 +224,8 @@ jobs:
224224
labels: ${{ steps.meta.outputs.labels }}
225225
sbom: true
226226
provenance: true
227-
outputs: type=oci,dest=companieshouse.tar
228-
platforms: linux/amd64
229-
- name: check file
230-
run: |
231-
ls
232-
echo "tag: ${{ steps.meta.outputs.tags }}"
227+
- name: Convert Image to Tar
228+
run: docker save -o companieshouse.tar ${{ steps.meta.outputs.tags }}
233229
- name: Scan Image
234230
uses: aquasecurity/[email protected]
235231
with:
@@ -242,8 +238,7 @@ jobs:
242238
- name: Push Image
243239
# if: ${{ github.event_name != 'pull_request' && steps.bump-version.outputs.is-dryrun-version-bumped == 'true' }} # Only push on main branch & when version is bumped with dryrun. We will create tags and creates separately after proper testing
244240
run: |
245-
buildctl image import < companieshouse.tar
246-
buildctl image push --name ${{ steps.meta.outputs.tags }}
241+
docker push ${{ steps.meta.outputs.tags }}
247242
248243
# create-release:
249244
# if: ${{ needs.docker-build-push.outputs.is-dryrun-version-bumped == 'true' }} # Only release when new version is available

0 commit comments

Comments
 (0)