From 88892ac425b3e3d445354e229caae2d52bf785e7 Mon Sep 17 00:00:00 2001 From: Clemens Hering Date: Sat, 15 Nov 2025 08:28:09 +0100 Subject: [PATCH] Added pipeline image scan --- .gitea/workflows/image-scan.yaml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.gitea/workflows/image-scan.yaml b/.gitea/workflows/image-scan.yaml index cc9ef5e..97c9a2f 100644 --- a/.gitea/workflows/image-scan.yaml +++ b/.gitea/workflows/image-scan.yaml @@ -12,7 +12,7 @@ env: # global: unkritische, strukturgebende Variablen CONTAINER_NAME: localhost/valtrix-website jobs: - build_and_deploy: + scan_image: runs-on: ubuntu-latest env: # Job-spezifisch: Secrets und sensible Werte SSH_PRIVATE_KEY: ${{ secrets.SSH_PRIVATE_KEY }} @@ -31,12 +31,12 @@ jobs: (ssh-keygen -F "$TARGET_HOST" >/dev/null || ssh-keyscan -H "$TARGET_HOST" >> ~/.ssh/known_hosts) || true (ssh-keygen -F gitea.smb-corp.de >/dev/null || ssh-keyscan -H gitea.smb-corp.de >> ~/.ssh/known_hosts) || true - - name: Build container on target host + - name: Scan container image with Trivy shell: bash run: | ssh -i ~/.ssh/id_ed25519 $TARGET_USER@$TARGET_HOST " set -euo pipefail export CONTAINER_NAME='$CONTAINER_NAME' echo 'Start Trivy Scan: '\$CONTAINER_NAME ' - trivy image \$CONTAINER_NAME:latest + trivy image localhost/valtrix-website:latest " \ No newline at end of file