diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index f81b1b63..7e8191e2 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -28,7 +28,7 @@ jobs: build-and-push-image: runs-on: large permissions: - contents: read + contents: write packages: write # This is used to complete the identity challenge # with sigstore/fulcio when running outside of PRs. @@ -116,6 +116,7 @@ jobs: format: 'github' output: 'dependency-results.sbom.json' github-pat: ${{ secrets.GITHUB_TOKEN }} + scanners: 'vuln' - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@master if: ${{ github.event_name != 'pull_request' }} @@ -124,6 +125,7 @@ jobs: format: 'sarif' output: 'trivy-results.sarif' severity: 'CRITICAL' + scanners: 'vuln' - name: Upload Trivy scan results to GitHub Security tab uses: github/codeql-action/upload-sarif@v2 if: ${{ github.event_name != 'pull_request' }}