Skip to content

Testing Docker Scout Security Action #13

Testing Docker Scout Security Action

Testing Docker Scout Security Action #13

Workflow file for this run

name: Docker Scout
on:
pull_request:
types: [opened, reopened, synchronize]
permissions:
pull-requests: write
jobs:
scout:
runs-on: ubuntu-latest
steps:
# - name: Checkout
# uses: actions/checkout@v4
# - name: Set up Docker Buildx
# uses: docker/setup-buildx-action@v3
- name: Login to DockerHub Container Registry
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USER }}
password: ${{ secrets.DOCKERHUB_PW }}
# - name: Build
# run: docker build --platform linux/amd64 -t getwilds/bwa:latest -f bwa/Dockerfile_latest .
- name: Docker Scout
id: docker-scout
uses: docker/scout-action@v1
with:
command: cves,recommendations
image: getwilds/bwa:latest
sarif-file: sarif.output.json
platform: linux/amd64
summary: true
- name: Upload SARIF result
id: upload-sarif
if: ${{ github.event_name != 'pull_request_target' }}
uses: github/codeql-action/upload-sarif@v2
with:
sarif_file: sarif.output.json