mirror of https://github.com/k3s-io/k3s
Tag PR image build as latest before scanning
This is less effort than passing the tag across steps 🤷♂️
Signed-off-by: Brad Davidson <brad.davidson@rancher.com>
pull/10799/head
parent
662799feec
commit
378edb939d
|
@ -27,11 +27,12 @@ jobs:
|
||||||
run: |
|
run: |
|
||||||
make local
|
make local
|
||||||
make package-image
|
make package-image
|
||||||
|
make tag-image-latest
|
||||||
|
|
||||||
- name: Run Trivy vulnerability scanner
|
- name: Run Trivy vulnerability scanner
|
||||||
uses: aquasecurity/trivy-action@0.24.0
|
uses: aquasecurity/trivy-action@0.24.0
|
||||||
with:
|
with:
|
||||||
image-ref: 'rancher/k3s'
|
image-ref: 'rancher/k3s:latest'
|
||||||
format: 'table'
|
format: 'table'
|
||||||
severity: "HIGH,CRITICAL"
|
severity: "HIGH,CRITICAL"
|
||||||
output: "trivy-report.txt"
|
output: "trivy-report.txt"
|
||||||
|
|
|
@ -0,0 +1,15 @@
|
||||||
|
#!/bin/bash
|
||||||
|
set -e
|
||||||
|
|
||||||
|
cd $(dirname $0)/..
|
||||||
|
|
||||||
|
. ./scripts/version.sh
|
||||||
|
|
||||||
|
TAG=${TAG:-${VERSION_TAG}${SUFFIX}}
|
||||||
|
REPO=${REPO:-rancher}
|
||||||
|
IMAGE_NAME=${IMAGE_NAME:-k3s}
|
||||||
|
|
||||||
|
IMAGE=${REPO}/${IMAGE_NAME}:${TAG}
|
||||||
|
LATEST=${REPO}/${IMAGE_NAME}:latest
|
||||||
|
docker image tag ${IMAGE} ${LATEST}
|
||||||
|
echo Tagged ${IMAGE} as ${LATEST}
|
Loading…
Reference in New Issue