🐛 Trivy scan fails when no critical vulnerabilities are detected #2251
Labels
bug
Something isn't working
data-platform-apps-and-tools
This issue is owned by Data Platform Apps and Tools
🧑💻 Apps & Tools BAU (Epic #1827)
Describe the bug.
Our scanning workflow is designed to fail when it detects
CRITICAL
https://github.com/ministryofjustice/data-platform/blob/74cd81562d66e5ad0e101cc08adce6cd39e1e142/.github/workflows/reusable-workflow-containers.yml#L183-L191
However it is failing regardless https://github.com/ministryofjustice/data-platform/actions/runs/6786028361/job/18445644387?pr=2227#step:5:15
To Reproduce
CRITICAL
vulnerabilitiesExpected Behaviour
Workflow passes
Additional context
I built the offending image locally and ran it through Trivy and the generated SARIF is as expected
Related: aquasecurity/trivy-action#281
The text was updated successfully, but these errors were encountered: