diff --git a/.github/workflows/trivy-analysis.yml b/.github/workflows/trivy-analysis.yml index 37db8bbd62d9..dc4ddba0bae4 100644 --- a/.github/workflows/trivy-analysis.yml +++ b/.github/workflows/trivy-analysis.yml @@ -19,18 +19,17 @@ jobs: fail-fast: false steps: - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@d43c1f16c00cfd3978dde6c07f4bbcf9eb6993ca + uses: aquasecurity/trivy-action@84384bd6e777ef152729993b8145ea352e9dd3ef with: image-ref: quay.io/keycloak/${{ matrix.container}}:nightly - format: template - template: '@/contrib/sarif.tpl' + format: sarif output: trivy-results.sarif severity: MEDIUM,CRITICAL,HIGH ignore-unfixed: true - security-checks: vuln timeout: 15m - name: Upload Trivy scan results to GitHub Security tab uses: github/codeql-action/upload-sarif@v3 with: sarif_file: trivy-results.sarif + category: ${{ matrix.container}}