name: Trivy Scan For OpenMetadata Ingestion Docker Image on: workflow_dispatch: concurrency: group: trivy-ingestion-scan-${{ github.run_id }} cancel-in-progress: true jobs: build-and-scan: runs-on: ubuntu-latest steps: - name: Free Disk Space (Ubuntu) uses: jlumbroso/free-disk-space@main with: tool-cache: false android: true dotnet: true haskell: true large-packages: false swap-storage: true docker-images: false - name: Checkout Repository uses: actions/checkout@v4 - name: Prepare for Docker Build id: prepare uses: ./.github/actions/prepare-for-docker-build with: image: openmetadata-ingestion tag: trivy is_ingestion: true - name: Build Docker Image run: | docker build -t openmetadata-ingestion:trivy -f ingestion/Dockerfile.ci . - name: Run Trivy Image Scan id: trivy_scan uses: aquasecurity/trivy-action@0.35.0 with: scan-type: "image" image-ref: openmetadata-ingestion:trivy hide-progress: false ignore-unfixed: true severity: "HIGH,CRITICAL" skip-dirs: "/opt/airflow/dags,/home/airflow/ingestion/pipelines" scan-ref: . format: 'template' template: "@.github/trivy/templates/github.tpl" output: "trivy-results-ingestion.md" env: TRIVY_DISABLE_VEX_NOTICE: "true"