Skip to content

upgrade twig for improved security #3633

upgrade twig for improved security

upgrade twig for improved security #3633

name: trivy-scan
on:
push:
branches:
- main
pull_request:
paths:
- "service-api/**"
- "service-admin/**"
- "service-front/**"
- "service-pdf/**"
- "shared/**"
- "tests/**"
- "cypress/**"
jobs:
filter-and-scan:
runs-on: ubuntu-latest
strategy:
fail-fast: true
matrix:
scan:
- name: service-api
path: "./service-api"
- name: service-admin
path: "./service-admin"
- name: service-front
path: "./service-front"
- name: service-pdf
path: "./service-pdf"
- name: shared
path: "./shared"
- name: tests
path: "./tests"
- name: cypress
path: "./cypress"
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Filter paths
uses: dorny/paths-filter@v3
id: filter
with:
filters: |
check: '${{ matrix.scan.path }}/**'
- name: Run Trivy vulnerability scanner for Code
if: steps.filter.outputs.check == 'true'
uses: aquasecurity/trivy-action@master
with:
scan-type: "fs"
ignore-unfixed: true
hide-progress: false
format: "sarif"
output: "${{ matrix.scan.name }}/trivy-results-code.sarif"
scan-ref: ${{ matrix.scan.path }}
- name: Upload Trivy scan results to GitHub Security tab
if: steps.filter.outputs.check == 'true'
uses: github/codeql-action/upload-sarif@v1
with:
sarif_file: "./${{ matrix.scan.name }}"