Skip to content

Commit 074d20b

Browse files
committed
Switch to CLI-based Sysdig scan using curl
1 parent 0f65abe commit 074d20b

File tree

1 file changed

+9
-5
lines changed

1 file changed

+9
-5
lines changed

.github/workflows/sysdig-scan.yml

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -27,15 +27,19 @@ jobs:
2727
docker build -t vote-image ./vote
2828
docker save vote-image -o vote-image.tar
2929
30-
- name: Download Sysdig CLI Scanner
30+
- name: Download Sysdig CLI Scanner (latest for amd64)
3131
run: |
32-
curl -LO https://download.sysdig.com/scanning/sysdig-cli-scanner/latest/linux/sysdig-cli-scanner
32+
curl -LO "https://download.sysdig.com/scanning/bin/sysdig-cli-scanner/$(curl -L -s https://download.sysdig.com/scanning/sysdig-cli-scanner/latest_version.txt)/linux/amd64/sysdig-cli-scanner"
3333
chmod +x sysdig-cli-scanner
3434
35-
- name: Scan Docker image from archive with Sysdig (binary)
35+
- name: Scan Docker image from archive
3636
run: |
37-
./sysdig-cli-scanner --standalone --input-file vote-image.tar vote-image:ci --console-log --detailed-policies-eval --full-vulns-table -e SECURE_API_TOKEN=${{ secrets.SYSDIG_SECURE_TOKEN }}
37+
./sysdig-cli-scanner --standalone --input-file vote-image.tar vote-image:ci --console-log --detailed-policies-eval --full-vulns-table
38+
env:
39+
SECURE_API_TOKEN: ${{ secrets.SYSDIG_SECURE_TOKEN }}
3840

3941
- name: Scan IaC (k8s-specifications)
4042
run: |
41-
./sysdig-cli-scanner --apiurl ${{ secrets.SYSDIG_API_URL }} --iac scan ./k8s-specifications -e SECURE_API_TOKEN=${{ secrets.SYSDIG_SECURE_TOKEN }}
43+
./sysdig-cli-scanner --apiurl ${{ secrets.SYSDIG_API_URL }} --iac scan ./k8s-specifications
44+
env:
45+
SECURE_API_TOKEN: ${{ secrets.SYSDIG_SECURE_TOKEN }}

0 commit comments

Comments
 (0)