try again
CI / Test Merge SARIF Files (pull_request) Successful in 4s
CI / Test Setup DB (pull_request) Successful in 6s
CI / Test Get Images From Files (pull_request) Successful in 5s
CI / Test scan-image (pull_request) Failing after 6s
CI / Test scan-fs (pull_request) Failing after 1m14s
CI / Test scan-config (pull_request) Failing after 1m2s

This commit is contained in:
2026-04-10 19:30:52 +02:00
parent 6e5f62d4dd
commit 954681c5af
7 changed files with 30 additions and 17 deletions
+4 -3
View File
@@ -10,11 +10,11 @@ inputs:
description: "Host path to the directory to scan (mounted read-only at /scan in the container)"
required: true
cache-dir:
description: "Host path to the Trivy cache directory (mounted read-only at /cache; use the same path as setup-db)"
description: "Trivy cache directory (bind-mounted read-only at /cache; default under runner.temp for Docker-in-Docker)"
required: false
default: "${{ runner.temp }}/trivy"
output-dir:
description: "Host directory where the report file is written (mounted read-write at /out)"
description: "Report directory (bind-mounted read-write at /out; created if missing)"
required: true
output-file:
description: "SARIF report file name only (no slashes); written under output-dir"
@@ -43,12 +43,13 @@ runs:
run: |
set -euo pipefail
case "$OUTPUT_FILE" in */*|".."*) echo "FAIL: output-file must be a single file name (no path separators)"; exit 1 ;; esac
mkdir -p "$CACHE_DIR_IN" "$OUTPUT_DIR_IN"
scan_path=$(realpath "$SCAN_PATH_IN")
cache_dir=$(realpath "$CACHE_DIR_IN")
mkdir -p "$OUTPUT_DIR_IN"
output_dir=$(realpath "$OUTPUT_DIR_IN")
test -d "$scan_path" || { echo "FAIL: scan-path is not a directory: $scan_path"; exit 1; }
test -d "$cache_dir" || { echo "FAIL: cache-dir is not a directory: $cache_dir"; exit 1; }
test -d "$output_dir" || { echo "FAIL: output-dir is not a directory: $output_dir"; exit 1; }
docker run --rm \
--name trivy-scan-config \