Skip to content

Merge pull request #87 from DanceMore/dependabot/cargo/clap-4.5.23 #95

Merge pull request #87 from DanceMore/dependabot/cargo/clap-4.5.23

Merge pull request #87 from DanceMore/dependabot/cargo/clap-4.5.23 #95

name: Security Scanners
on:
push:
branches:
- main
tags:
- '*'
paths-ignore:
- '**.md'
jobs:
scan:
runs-on: ubuntu-latest
steps:
- name: checkout code
uses: actions/checkout@v2
- name: Set up Rust
uses: actions-rs/toolchain@v1
with:
profile: minimal
toolchain: stable
- name: Build Rust project
run: cargo build --release
# - name: Install Cargo Geiger
# run: cargo install cargo-geiger
#
# - name: Run Cargo Geiger
# run: cargo geiger
- name: Perform Scan
uses: ShiftLeftSecurity/scan-action@master
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master
with:
image-ref: 'ghcr.io/dancemore/dancemore/jukectl:latest'
format: 'table'
exit-code: '1'
ignore-unfixed: true
vuln-type: 'os,library'
severity: 'CRITICAL,HIGH'