Skip to content

Bump phpstan/phpstan from 2.2.8 to 2.2.16 #221

Bump phpstan/phpstan from 2.2.8 to 2.2.16

Bump phpstan/phpstan from 2.2.8 to 2.2.16 #221

Workflow file for this run

# https://github.com/aquasecurity/trivy-action
name: Trivy Scan
on:
push:
branches: [ "main" ]
pull_request:
# The branches below must be a subset of the branches above
branches: [ "main" ]
schedule:
- cron: '43 11 * * 6'
permissions:
contents: read # for actions/checkout to fetch code
security-events: write # for github/codeql-action/upload-sarif to upload SARIF results
actions: read # only required for a private repository by github/codeql-action/upload-sarif to get the Action run status
env:
IMAGE_NAME: appwrite/base
REGISTRY: docker.io
jobs:
scheduled_trivy:
runs-on: ubuntu-24.04
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Build an image from Dockerfile
run: |
docker image build --target final --tag ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }} .
- name: Run Trivy vulnerability scanner (sarif report)
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
with:
exit-code: '1'
format: 'sarif'
ignore-unfixed: true
image-ref: '${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }}'
output: 'trivy-image-results.sarif'
severity: 'CRITICAL,HIGH,MEDIUM'
# https://github.com/github/codeql-action/blob/main/upload-sarif/action.yml
- name: Upload Trivy scan results
if: always()
uses: github/codeql-action/upload-sarif@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7
with:
sarif_file: '.'