fix: try to fix trivy scanner

This commit is contained in:
Alexandre Teles 2022-09-30 20:42:34 -03:00
parent 2c83789cd7
commit 2d6ec6d5e0
No known key found for this signature in database
GPG Key ID: 260D825F04C0527E
4 changed files with 19 additions and 9 deletions

View File

@ -32,10 +32,23 @@ jobs:
with: with:
ref: ${{ env.default_branch }} ref: ${{ env.default_branch }}
- name: Set up Python
uses: actions/setup-python@v4
with:
python-version: '3.10.7'
- name: Install dependencies
run: |
python -m pip install --upgrade pip
if [ -f requirements.txt ];
then pip install -r requirements.txt;
fi
echo "CODEQL_PYTHON=$(which python)" >> $GITHUB_ENV
- name: Initialize CodeQL - name: Initialize CodeQL
uses: github/codeql-action/init@v2 uses: github/codeql-action/init@v2
with: with:
languages: ${{ matrix.language }} languages: ${{ matrix.language }}
setup-python-dependencies: false
- name: Autobuild - name: Autobuild
uses: github/codeql-action/autobuild@v2 uses: github/codeql-action/autobuild@v2

View File

@ -65,13 +65,12 @@ jobs:
file: ./Dockerfile file: ./Dockerfile
platforms: linux/amd64,linux/arm64/v8 platforms: linux/amd64,linux/arm64/v8
push: false push: false
tags: ${{ steps.meta.outputs.tags }} tags: revanced/revanced-releases-api:dev
labels: ${{ steps.meta.outputs.labels }}
- name: Run Trivy vulnerability scanner - name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master uses: aquasecurity/trivy-action@master
with: with:
image-ref: ${{ steps.meta.outputs.tags }} image-ref: revanced/revanced-releases-api:dev
format: 'sarif' format: 'sarif'
output: 'trivy-results.sarif' output: 'trivy-results.sarif'

View File

@ -66,13 +66,12 @@ jobs:
file: ./Dockerfile file: ./Dockerfile
platforms: linux/amd64,linux/arm64/v8 platforms: linux/amd64,linux/arm64/v8
push: false push: false
tags: ${{ steps.meta.outputs.tags }} tags: revanced/revanced-releases-api:dev
labels: ${{ steps.meta.outputs.labels }}
- name: Run Trivy vulnerability scanner - name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master uses: aquasecurity/trivy-action@master
with: with:
image-ref: ${{ steps.meta.outputs.tags }} image-ref: revanced/revanced-releases-api:dev
format: 'sarif' format: 'sarif'
output: 'trivy-results.sarif' output: 'trivy-results.sarif'

View File

@ -61,13 +61,12 @@ jobs:
file: ./Dockerfile file: ./Dockerfile
platforms: linux/amd64,linux/arm64/v8 platforms: linux/amd64,linux/arm64/v8
push: false push: false
tags: ${{ steps.meta.outputs.tags }} tags: revanced/revanced-releases-api:dev
labels: ${{ steps.meta.outputs.labels }}
- name: Run Trivy vulnerability scanner - name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master uses: aquasecurity/trivy-action@master
with: with:
image-ref: ${{ steps.meta.outputs.tags }} image-ref: revanced/revanced-releases-api:dev
format: 'sarif' format: 'sarif'
output: 'trivy-results.sarif' output: 'trivy-results.sarif'