diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 5c72e82..cd63251 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -63,10 +63,12 @@ jobs: - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@915b19bbe73b92a6cf82a1bc12b087c9a19a5fe2 # v0.28.0 if: github.event_name != 'pull_request' + env: + TRIVY_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-db:2 with: image-ref: ${{ inputs.image-name }}:${{ steps.meta.outputs.version }} - format: 'table' - exit-code: '1' + format: "table" + exit-code: "1" ignore-unfixed: true - vuln-type: 'os,library' - severity: 'CRITICAL,HIGH' + vuln-type: "os,library" + severity: "CRITICAL,HIGH"