fix(ci): make the YAML Trivy suppressions actually apply (#12326)

This commit is contained in:
César Arroba
2026-08-04 13:05:46 +02:00
committed by GitHub
parent c610d9ac31
commit 5cf49805a2
+6 -4
View File
@@ -64,8 +64,9 @@ runs:
scanners: 'vuln'
timeout: '5m'
version: 'v0.71.2'
# Explicit: Trivy only auto-loads the classic .trivyignore, never the YAML one.
trivyignores: '.trivyignore.yaml'
# Not trivyignores: that input drops the .yaml extension Trivy parses by.
env:
TRIVY_IGNOREFILE: '.trivyignore.yaml'
- name: Run Trivy vulnerability scan (SARIF)
if: inputs.upload-sarif == 'true' && github.event_name == 'push'
@@ -79,8 +80,9 @@ runs:
scanners: 'vuln'
timeout: '5m'
version: 'v0.71.2'
# Explicit: Trivy only auto-loads the classic .trivyignore, never the YAML one.
trivyignores: '.trivyignore.yaml'
# Not trivyignores: that input drops the .yaml extension Trivy parses by.
env:
TRIVY_IGNOREFILE: '.trivyignore.yaml'
- name: Upload Trivy results to GitHub Security tab
if: inputs.upload-sarif == 'true' && github.event_name == 'push'