File tree Expand file tree Collapse file tree 1 file changed +4
-9
lines changed Expand file tree Collapse file tree 1 file changed +4
-9
lines changed Original file line number Diff line number Diff line change 12
12
13
13
jobs :
14
14
scan :
15
- name : Sysdig Scan Docker + IaC (loaded image method )
15
+ name : Sysdig Scan Docker + IaC (with docker.sock )
16
16
runs-on : ubuntu-latest
17
17
18
18
steps :
@@ -25,16 +25,11 @@ jobs:
25
25
- name : Build vote image
26
26
run : |
27
27
docker build -t vote-image ./vote
28
- docker save vote-image -o vote-image.tar
28
+ docker tag vote-image vote-image:ci
29
29
30
- - name : Load and tag image
30
+ - name : Scan Docker image using docker.sock
31
31
run : |
32
- docker load -i vote-image.tar
33
- docker tag vote-image:latest vote-image:ci
34
-
35
- - name : Scan Docker image using tag
36
- run : |
37
- docker run --rm -e SECURE_API_TOKEN=${{ secrets.SYSDIG_SECURE_TOKEN }} quay.io/sysdig/sysdig-cli-scanner:latest --apiurl ${{ secrets.SYSDIG_API_URL }} vote-image:ci
32
+ docker run --rm -v /var/run/docker.sock:/var/run/docker.sock -e SECURE_API_TOKEN=${{ secrets.SYSDIG_SECURE_TOKEN }} quay.io/sysdig/sysdig-cli-scanner:latest --apiurl ${{ secrets.SYSDIG_API_URL }} vote-image:ci
38
33
39
34
- name : Scan IaC (k8s-specifications)
40
35
run : |
You can’t perform that action at this time.
0 commit comments