Skip to content

Commit 8f13308

Browse files
authored
Merge pull request #11 from broadinstitute/add-trivy-ignore-policy
Add Trivy ignore policy for batch pipeline container context
2 parents 36c8594 + 937a676 commit 8f13308

2 files changed

Lines changed: 396 additions & 0 deletions

File tree

.github/workflows/docker-build.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -122,6 +122,9 @@ jobs:
122122
- name: Pull image
123123
run: docker pull ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ steps.tag.outputs.tag }}
124124

125+
- name: Checkout (for ignore policy)
126+
uses: actions/checkout@v4
127+
125128
- name: Run Trivy vulnerability scanner (table)
126129
uses: aquasecurity/trivy-action@master
127130
with:
@@ -130,6 +133,7 @@ jobs:
130133
severity: CRITICAL,HIGH
131134
exit-code: '1'
132135
ignore-unfixed: true
136+
ignore-policy: .trivy-ignore-policy.rego
133137

134138
- name: Run Trivy vulnerability scanner (SARIF)
135139
uses: aquasecurity/trivy-action@master
@@ -140,6 +144,7 @@ jobs:
140144
output: trivy-results.sarif
141145
severity: CRITICAL,HIGH
142146
ignore-unfixed: true
147+
ignore-policy: .trivy-ignore-policy.rego
143148

144149
- name: Upload results to GitHub Security tab
145150
uses: github/codeql-action/upload-sarif@v4

0 commit comments

Comments
 (0)