From 935fb59592211de1aa2b97c038deee36866a7f25 Mon Sep 17 00:00:00 2001 From: dandelany Date: Thu, 5 Sep 2024 10:31:27 -0700 Subject: [PATCH] publish workflow: checkout repo during scan step to get trivyignore --- .github/workflows/publish.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 64d29e1e6d..064a41d1e6 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -147,6 +147,8 @@ jobs: fail-fast: false name: scan ${{ matrix.image }} steps: + - uses: actions/checkout@v4 + - name: Scan ${{ matrix.image }} for vulnerabilities uses: aquasecurity/trivy-action@0.24.0 with: