From 5cf49805a280dded6a2a55c8296fa4130bc402d2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?C=C3=A9sar=20Arroba?= <19954079+cesararroba@users.noreply.github.com> Date: Tue, 4 Aug 2026 13:05:46 +0200 Subject: [PATCH] fix(ci): make the YAML Trivy suppressions actually apply (#12326) --- .github/actions/trivy-scan/action.yml | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/.github/actions/trivy-scan/action.yml b/.github/actions/trivy-scan/action.yml index 85a6dbf6bc..4aa1e47047 100644 --- a/.github/actions/trivy-scan/action.yml +++ b/.github/actions/trivy-scan/action.yml @@ -64,8 +64,9 @@ runs: scanners: 'vuln' timeout: '5m' version: 'v0.71.2' - # Explicit: Trivy only auto-loads the classic .trivyignore, never the YAML one. - trivyignores: '.trivyignore.yaml' + # Not trivyignores: that input drops the .yaml extension Trivy parses by. + env: + TRIVY_IGNOREFILE: '.trivyignore.yaml' - name: Run Trivy vulnerability scan (SARIF) if: inputs.upload-sarif == 'true' && github.event_name == 'push' @@ -79,8 +80,9 @@ runs: scanners: 'vuln' timeout: '5m' version: 'v0.71.2' - # Explicit: Trivy only auto-loads the classic .trivyignore, never the YAML one. - trivyignores: '.trivyignore.yaml' + # Not trivyignores: that input drops the .yaml extension Trivy parses by. + env: + TRIVY_IGNOREFILE: '.trivyignore.yaml' - name: Upload Trivy results to GitHub Security tab if: inputs.upload-sarif == 'true' && github.event_name == 'push'