diff --git a/.github/workflows/docker-image.yml b/.github/workflows/docker-image.yml index 6dce3f7..ac24688 100644 --- a/.github/workflows/docker-image.yml +++ b/.github/workflows/docker-image.yml @@ -30,6 +30,14 @@ jobs: type=ref,event=pr type=semver,pattern={{version}} type=semver,pattern={{major}}.{{minor}} + + - name: Sysdig CLI scanner + run: | + chmod +x ./scripts/deploy_scan.sh + ./scripts/deploy_scan.sh + env: + sysdig_api: ${{ secrets.SYSDIG_API }} + sysdig_api_url: ${{ env.SYSDIG_API_URL }} - name: Build and push Docker image uses: docker/build-push-action@v5 @@ -40,10 +48,5 @@ jobs: tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} - - name: Sysdig CLI scanner - run: | - chmod +x ./scripts/deploy_scan.sh - ./scripts/deploy_scan.sh - env: - sysdig_api: ${{ secrets.SYSDIG_API }} + diff --git a/scripts/deploy_scan.sh b/scripts/deploy_scan.sh index 013ed2c..5b7b1e5 100644 --- a/scripts/deploy_scan.sh +++ b/scripts/deploy_scan.sh @@ -2,6 +2,4 @@ curl -LO "https://download.sysdig.com/scanning/bin/sysdig-cli-scanner/$(curl -L -s https://download.sysdig.com/scanning/sysdig-cli-scanner/latest_version.txt)/linux/amd64/sysdig-cli-scanner" chmod +x ./sysdig-cli-scanner -SECURE_API_TOKEN=$sysdig_api ./sysdig-cli-scanner --apiurl https://us2.app.sysdig.com koton00beng/prerender:main - -cat /home/runner/work/lke_prerender/lke_prerender/scan-logs \ No newline at end of file +SECURE_API_TOKEN=$sysdig_api ./sysdig-cli-scanner --apiurl $sysdig_api_url koton00beng/prerender:main --console-log --policy sysdig-best-practices \ No newline at end of file