Skip to content

Commit 082a557

Browse files
committed
Ignore pipeline files when scanning with Trivy
Trivy was detecting dependencies inside the Git checkout for Trivy report templates. Also switch to "repository" scanning as it is more appropriate here. See: https://trivy.dev/v0.64/docs/target/repository#rationale
1 parent 9e67529 commit 082a557

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

.gitlab-ci.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -203,7 +203,7 @@ trivy:
203203
# Trivy needs a populated Go module cache to detect Go module licenses.
204204
- go mod download
205205
- >-
206-
trivy filesystem . --exit-code 1
206+
trivy repository . --exit-code 1 --skip-dirs .gitlab-remotes
207207
--scanners license,vuln
208208
--ignore-unfixed
209209
--no-progress

0 commit comments

Comments
 (0)