update trivy action

This commit is contained in:
Astound 2025-01-20 07:17:10 +08:00
parent 1673c569e6
commit da120ee0be
Signed by: kaiser
GPG Key ID: 97504AF0027B1A56
2 changed files with 8 additions and 7 deletions

View File

@ -88,14 +88,13 @@ jobs:
${{ secrets.DOCKER_REGISTRY_USER}}/hypermirror:v${{ steps.meta.outputs.IMAGE_VERSION }}
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master
uses: astounds/trivy-action@v1
with:
image-ref: ${{ secrets.DOCKER_REGISTRY_USER}}/hypermirror:latest
image: ${{ secrets.DOCKER_REGISTRY_USER}}/hypermirror:latest
severity: 'CRITICAL,HIGH'
pkg-types: 'os'
format: 'table'
exit-code: '1'
ignore-unfixed: true
vuln-type: 'os'
severity: 'CRITICAL,HIGH'
- name: Push Docker image
uses: docker/build-push-action@v6

View File

@ -4,12 +4,14 @@ RUN pacman -Syu --noconfirm && pacman -S --noconfirm \
nginx rsync cronie util-linux findutils && \
pacman -Scc --noconfirm
RUN mkdir /srv/repo
# Create the /srv/repo directory to store repository data
RUN mkdir -p /srv/repo
COPY entrypoint.bash /
RUN chmod u+x /entrypoint.bash
# Define a mount point for the repository data
VOLUME /srv/repo
# Expose port 80 for the web server
EXPOSE 80
ENTRYPOINT ["/entrypoint.bash"]