Skip to content

Commit

Permalink
Update cd.yml
Browse files Browse the repository at this point in the history
  • Loading branch information
Cedric-Magnan authored Nov 9, 2023
1 parent e176653 commit 09ac271
Showing 1 changed file with 3 additions and 10 deletions.
13 changes: 3 additions & 10 deletions .github/workflows/cd.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,32 +4,27 @@ on:
types: [published]

jobs:

docker:

permissions:
contents: read # for actions/checkout to fetch code
security-events: write # for github/codeql-action/upload-sarif to upload SARIF results
runs-on: ubuntu-latest

steps:

- name: Checkout
uses: actions/checkout@v2

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v1

- name: Login to Github Container Registry
uses: docker/login-action@v1
with:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
registry: ghcr.io

- name: Set tag name
id: tag
run: echo ::set-output name=tag_name::${GITHUB_REF#*\/*\/}
env:
GITHUB_REF: ${{ github.ref }}

- name: Build and push
uses: docker/build-push-action@v2
with:
Expand All @@ -41,14 +36,12 @@ jobs:
ghcr.io/artefactory/github_tests_validator_app:latest
cache-from: type=registry,ref=ghcr.io/artefactory/github_tests_validator_app:latest
cache-to: type=inline

- name: Scan image
uses: anchore/scan-action@v3
id: scan
with:
image: "ghcr.io/artefactory/github_tests_validator_app:${{ steps.tag.outputs.tag_name }}"
severity-cutoff: "low"

- name: upload Anchore scan SARIF report
if: success() || failure()
uses: github/codeql-action/upload-sarif@v2
Expand Down

0 comments on commit 09ac271

Please sign in to comment.