fix: trivy workflow
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
---
|
||||
name: Build, Scan and Publish Docker Image
|
||||
name: Lint, Build, Scan and Publish Docker Image
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
@@ -8,6 +8,29 @@ on:
|
||||
- 'v*'
|
||||
|
||||
jobs:
|
||||
lint:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Install Ruff
|
||||
run: pip install ruff
|
||||
|
||||
- name: Run Ruff (Lint & Format Check)
|
||||
run: |
|
||||
ruff check .
|
||||
ruff format --check .
|
||||
|
||||
- name: Lint Dockerfile (Hadolint)
|
||||
uses: hadolint/hadolint-action@v3.1.0
|
||||
with:
|
||||
dockerfile: Dockerfile
|
||||
|
||||
- name: Security Lint Dockerfile (Trivy)
|
||||
run: |
|
||||
trivy config --server http://trivy-server:8080 .
|
||||
|
||||
build-and-push:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
|
||||
Reference in New Issue
Block a user