Skip to content

Commit f61bee0

Browse files
back vce scan
Signed-off-by: Nikita Korolev <nikita.korolev@flant.com>
1 parent ccef59d commit f61bee0

1 file changed

Lines changed: 20 additions & 0 deletions

File tree

.github/workflows/dev_module_build.yml

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -339,3 +339,23 @@ jobs:
339339
module_source: ${{ vars.DEV_MODULE_SOURCE}}
340340
module_name: ${{ vars.MODULE_NAME }}
341341
module_tag: "$MODULES_MODULE_TAG"
342+
343+
cve_scan_on_pr:
344+
name: Trivy images check
345+
runs-on: ${{ fromJSON(needs.set_vars.outputs.runner_type)}}
346+
needs:
347+
- set_vars
348+
- dev_setup_build
349+
steps:
350+
- uses: actions/checkout@v4
351+
- uses: deckhouse/modules-actions/cve_scan@v2
352+
with:
353+
image: ${{ vars.DEV_MODULE_SOURCE }}/${{ vars.MODULE_NAME }}
354+
tag: ${{needs.set_vars.outputs.modules_module_tag}}
355+
module_name: ${{ vars.MODULE_NAME }}
356+
dd_url: ${{vars.DEFECTDOJO_HOST}}
357+
dd_token: ${{secrets.DEFECTDOJO_API_TOKEN}}
358+
trivy_registry: ${{ vars.PROD_REGISTRY }}
359+
trivy_registry_user: ${{ vars.PROD_MODULES_REGISTRY_LOGIN }}
360+
trivy_registry_password: ${{ secrets.PROD_MODULES_REGISTRY_PASSWORD }}
361+
deckhouse_private_repo: ${{vars.DECKHOUSE_PRIVATE_REPO}}

0 commit comments

Comments
 (0)