From d62bf71820a528a2fe1f48970d249f77c1d3b42f Mon Sep 17 00:00:00 2001 From: Christian Nicolai Date: Thu, 8 Oct 2020 12:25:38 +0200 Subject: [PATCH] ci: ignore false-positive 3rd party lockfiles for trivy --- .github/workflows/vulnscan.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/vulnscan.yml b/.github/workflows/vulnscan.yml index 0891f2b..11b7f47 100644 --- a/.github/workflows/vulnscan.yml +++ b/.github/workflows/vulnscan.yml @@ -24,7 +24,7 @@ jobs: trivy image --download-db-only - name: Scan vulnerabilities using Trivy env: - TRIVY_SKIP_DIRS: '/usr/lib/ruby/gems/2.7.0/gems/jaeger-client-0.10.0/crossdock,/usr/lib/ruby/gems/2.7.0/gems/jaeger-client-1.0.0/crossdock' + TRIVY_SKIP_DIRS: 'usr/lib/ruby/gems/2.7.0/gems/jaeger-client-0.10.0/crossdock,usr/lib/ruby/gems/2.7.0/gems/jaeger-client-1.0.0/crossdock,usr/lib/ruby/gems/2.7.0/gems/jaeger-client-1.1.0/crossdock' run: | trivy --version