This commit is contained in:
Matthew McClaskey 2023-11-22 16:57:46 +00:00
parent 37c8fb5f40
commit 3303760b80

View File

@ -134,7 +134,6 @@ test_{{ IMAGE.name1 }}_{{ IMAGE.name2 }}:
{% for IMAGE in multiImages %} {% for IMAGE in multiImages %}
scan_{{ IMAGE.name1 }}_{{ IMAGE.name2 }}: scan_{{ IMAGE.name1 }}_{{ IMAGE.name2 }}:
stage: scan stage: scan
when: always
script: script:
- apk add bash - apk add bash
- (cd ci-scripts && bash download-trivy) - (cd ci-scripts && bash download-trivy)
@ -156,7 +155,6 @@ scan_{{ IMAGE.name1 }}_{{ IMAGE.name2 }}:
- when: manual - when: manual
needs: needs:
- build_{{ IMAGE.name1 }}_{{ IMAGE.name2 }} - build_{{ IMAGE.name1 }}_{{ IMAGE.name2 }}
when: on_success
tags: tags:
- oci-fixed-amd - oci-fixed-amd
retry: 1 retry: 1
@ -172,7 +170,6 @@ scan_{{ IMAGE.name1 }}_{{ IMAGE.name2 }}:
{% for IMAGE in singleImages %} {% for IMAGE in singleImages %}
scan_{{ IMAGE.name1 }}_{{ IMAGE.name2 }}: scan_{{ IMAGE.name1 }}_{{ IMAGE.name2 }}:
stage: scan stage: scan
when: always
script: script:
- apk add bash - apk add bash
- (cd ci-scripts && bash download-trivy) - (cd ci-scripts && bash download-trivy)
@ -194,13 +191,10 @@ scan_{{ IMAGE.name1 }}_{{ IMAGE.name2 }}:
- when: manual - when: manual
needs: needs:
- build_{{ IMAGE.name1 }}_{{ IMAGE.name2 }} - build_{{ IMAGE.name1 }}_{{ IMAGE.name2 }}
rules:
- if: ($RUN_VULNERABILITY_SCANS == "true" || $CI_COMMIT_BRANCH == "develop")
artifacts: artifacts:
reports: reports:
junit: junit:
- $CI_PROJECT_DIR/trivy-report.xml - $CI_PROJECT_DIR/trivy-report.xml
when: on_success
tags: tags:
- oci-fixed-amd - oci-fixed-amd
retry: 1 retry: 1