From ca3e746754b5fff6ab86b7dd06edd0bc493a8860 Mon Sep 17 00:00:00 2001 From: ppawlowski Date: Sun, 22 Sep 2024 21:42:14 +0200 Subject: [PATCH 1/4] Test trivy action --- .github/workflows/flowforge-container.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/flowforge-container.yml b/.github/workflows/flowforge-container.yml index c77771dd..11f4fddc 100644 --- a/.github/workflows/flowforge-container.yml +++ b/.github/workflows/flowforge-container.yml @@ -29,7 +29,7 @@ concurrency: jobs: build: name: Build single-architecture container images - uses: flowfuse/github-actions-workflows/.github/workflows/build_container_image.yml@v0.30.0 + uses: flowfuse/github-actions-workflows/.github/workflows/build_container_image.yml@fix-trivy-custom-vuln-db with: image_name: 'forge-k8s' package_dependencies: | From f45304eda49b27a611c3e993d9cfccefe2ad210a Mon Sep 17 00:00:00 2001 From: ppawlowski Date: Sun, 22 Sep 2024 22:07:49 +0200 Subject: [PATCH 2/4] Test trivy action --- .github/workflows/flowforge-container.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/flowforge-container.yml b/.github/workflows/flowforge-container.yml index 11f4fddc..dfbd9d3e 100644 --- a/.github/workflows/flowforge-container.yml +++ b/.github/workflows/flowforge-container.yml @@ -26,6 +26,7 @@ concurrency: group: ${{ github.workflow }}-${{ github.ref_name }} cancel-in-progress: true + jobs: build: name: Build single-architecture container images From eea23ca1e37144a20223d86d3252adb7e041d77a Mon Sep 17 00:00:00 2001 From: ppawlowski Date: Sun, 22 Sep 2024 22:34:53 +0200 Subject: [PATCH 3/4] Disable trivy scan --- .github/workflows/fileserver-container.yml | 2 +- .github/workflows/flowforge-container.yml | 2 +- .github/workflows/nodered-container.yml | 8 ++++---- 3 files changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/workflows/fileserver-container.yml b/.github/workflows/fileserver-container.yml index 54c153f3..65ad549d 100644 --- a/.github/workflows/fileserver-container.yml +++ b/.github/workflows/fileserver-container.yml @@ -37,7 +37,7 @@ jobs: build_context: 'file-server' build_platform: "linux/amd64" npm_registry_url: ${{ vars.PUBLIC_NPM_REGISTRY_URL }} - scan_image: true + scan_image: false secrets: npm_registry_auth_token: ${{ secrets.NPM_PUBLISH_TOKEN }} temporary_registry_token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/flowforge-container.yml b/.github/workflows/flowforge-container.yml index dfbd9d3e..edb05379 100644 --- a/.github/workflows/flowforge-container.yml +++ b/.github/workflows/flowforge-container.yml @@ -39,7 +39,7 @@ jobs: build_context: 'flowforge-container' build_platform: "linux/amd64" npm_registry_url: ${{ vars.PUBLIC_NPM_REGISTRY_URL }} - scan_image: true + scan_image: false secrets: npm_registry_auth_token: ${{ secrets.NPM_PUBLISH_TOKEN }} temporary_registry_token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/nodered-container.yml b/.github/workflows/nodered-container.yml index 61c1c4a3..336beb64 100644 --- a/.github/workflows/nodered-container.yml +++ b/.github/workflows/nodered-container.yml @@ -39,7 +39,7 @@ jobs: build_context: 'node-red-container' build_platform: "linux/arm64" npm_registry_url: ${{ vars.PUBLIC_NPM_REGISTRY_URL }} - scan_image: true + scan_image: false secrets: npm_registry_auth_token: ${{ secrets.NPM_PUBLISH_TOKEN }} temporary_registry_token: ${{ secrets.GITHUB_TOKEN }} @@ -93,7 +93,7 @@ jobs: build_context: 'node-red-container' build_platform: "linux/arm64" npm_registry_url: ${{ vars.PUBLIC_NPM_REGISTRY_URL }} - scan_image: true + scan_image: false secrets: npm_registry_auth_token: ${{ secrets.NPM_PUBLISH_TOKEN }} temporary_registry_token: ${{ secrets.GITHUB_TOKEN }} @@ -146,7 +146,7 @@ jobs: build_context: 'node-red-container' build_platform: "linux/arm64" npm_registry_url: ${{ vars.PUBLIC_NPM_REGISTRY_URL }} - scan_image: true + scan_image: false secrets: npm_registry_auth_token: ${{ secrets.NPM_PUBLISH_TOKEN }} temporary_registry_token: ${{ secrets.GITHUB_TOKEN }} @@ -199,7 +199,7 @@ jobs: build_context: 'node-red-container' build_platform: "linux/arm64" npm_registry_url: ${{ vars.PUBLIC_NPM_REGISTRY_URL }} - scan_image: true + scan_image: false secrets: npm_registry_auth_token: ${{ secrets.NPM_PUBLISH_TOKEN }} temporary_registry_token: ${{ secrets.GITHUB_TOKEN }} From a0cca35f13fce88980e71fe75bb0cfc9440277f6 Mon Sep 17 00:00:00 2001 From: ppawlowski Date: Sun, 22 Sep 2024 22:36:15 +0200 Subject: [PATCH 4/4] Rollback reusable workflow version reference --- .github/workflows/flowforge-container.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/flowforge-container.yml b/.github/workflows/flowforge-container.yml index edb05379..d0a41770 100644 --- a/.github/workflows/flowforge-container.yml +++ b/.github/workflows/flowforge-container.yml @@ -30,7 +30,7 @@ concurrency: jobs: build: name: Build single-architecture container images - uses: flowfuse/github-actions-workflows/.github/workflows/build_container_image.yml@fix-trivy-custom-vuln-db + uses: flowfuse/github-actions-workflows/.github/workflows/build_container_image.yml@v0.30.0 with: image_name: 'forge-k8s' package_dependencies: |