Skip to content

Commit 558861b

Browse files
committed
Adding scanning of built container
1 parent de33c6f commit 558861b

File tree

1 file changed

+17
-0
lines changed

1 file changed

+17
-0
lines changed

.github/workflows/docker-release-3.0.yml

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -73,3 +73,20 @@ jobs:
7373
docker push $DOCKER_GENERATOR_FULL_IMAGE_NAME:$${{ env.TAG }}-root
7474
env:
7575
TAG: ${{ github.event.inputs.tag }}
76+
77+
scan-with-lacework:
78+
name: Trigger LaceWork Scanning
79+
runs-on: ubuntu-latest
80+
81+
needs: [ build_push_docker_release_30 ]
82+
if: success()
83+
84+
steps:
85+
- name: Trigger LaceWork Scanning using a different method
86+
run: |
87+
docker run -e LW_ACCOUNT_NAME=$LW_ACCOUNT_NAME -e LW_ACCESS_TOKEN=$LW_ACCESS_TOKEN -e LW_SCANNER_DISABLE_UPDATES=false -v /var/run/docker.sock:/var/run/docker.sock lacework/lacework-inline-scanner:latest image evaluate swaggerapi/swagger-codegen-cli latest --docker-server index.docker.io --docker-username $docker_user --docker-password $docker_password > /dev/null 2>&1
88+
env:
89+
LW_ACCOUNT_NAME: ${{ secrets.LW_ACCOUNT_NAME }}
90+
LW_ACCESS_TOKEN: ${{ secrets.LW_ACCESS_TOKEN }}
91+
docker_user: ${{ secrets.DOCKERHUB_SB_USERNAME}}
92+
docker_password: ${{ secrets.DOCKERHUB_SB_PASSWORD}}

0 commit comments

Comments
 (0)