9
9
jobs :
10
10
scan :
11
11
runs-on : ubuntu-latest
12
- name : Scan vote / worker / result + IaC
12
+ name : Scan vote / worker / result + IaC (stable, no version pin)
13
13
14
14
steps :
15
15
- name : Checkout source
33
33
sysdig-secure-token : ${{ secrets.SYSDIG_SECURE_TOKEN }}
34
34
sysdig-secure-url : ${{ secrets.SYSDIG_API_URL }}
35
35
stop-on-processing-error : true
36
- cli-scanner-version : 1.22.3
37
36
38
37
# Scan worker
39
38
- name : Scan worker image with Sysdig
43
42
sysdig-secure-token : ${{ secrets.SYSDIG_SECURE_TOKEN }}
44
43
sysdig-secure-url : ${{ secrets.SYSDIG_API_URL }}
45
44
stop-on-processing-error : true
46
- cli-scanner-version : 1.22.3
47
45
48
46
# Scan result
49
47
- name : Scan result image with Sysdig
@@ -53,17 +51,14 @@ jobs:
53
51
sysdig-secure-token : ${{ secrets.SYSDIG_SECURE_TOKEN }}
54
52
sysdig-secure-url : ${{ secrets.SYSDIG_API_URL }}
55
53
stop-on-processing-error : true
56
- cli-scanner-version : 1.22.3
57
54
58
- # Scan IaC
55
+ # Scan IaC (k8s-specifications)
59
56
- name : Scan Kubernetes IaC manifests
60
57
uses : sysdiglabs/scan-action@v6
61
- continue-on-error : true # IaC scan failure should not block main scan
58
+ continue-on-error : true
62
59
with :
63
60
mode : iac
64
61
iac-scan-path : k8s-specifications
65
62
sysdig-secure-token : ${{ secrets.SYSDIG_SECURE_TOKEN }}
66
63
sysdig-secure-url : ${{ secrets.SYSDIG_API_URL }}
67
64
stop-on-processing-error : true
68
- cli-scanner-version : 1.23.3
69
-
0 commit comments