@@ -191,7 +191,7 @@ jobs:
191191 if : ${{ steps.check_languages.outputs.uses_poetry == 'true' }}
192192 with :
193193 scan-type : " fs"
194- skip-files : " **/poetry.lock,**/go.sum ,**/pom.xml,**/package-lock.json"
194+ skip-files : " **/poetry.lock,**/go.mod ,**/pom.xml,**/package-lock.json"
195195 scan-ref : " ."
196196 severity : " CRITICAL,HIGH"
197197 scanners : " license"
@@ -211,7 +211,7 @@ jobs:
211211 if : ${{ steps.check_languages.outputs.uses_node == 'true' }}
212212 with :
213213 scan-type : " fs"
214- skip-files : " **/poetry.lock,**/go.sum ,**/pom.xml"
214+ skip-files : " **/poetry.lock,**/go.mod ,**/pom.xml"
215215 scan-ref : " ."
216216 severity : " CRITICAL,HIGH"
217217 scanners : " license"
@@ -220,6 +220,11 @@ jobs:
220220 exit-code : " 1"
221221 list-all-pkgs : " false"
222222 trivy-config : trivy.yaml
223+ - name : download go dependencies
224+ if : ${{ steps.check_languages.outputs.uses_go == 'true' }}
225+ run : |
226+ cd src
227+ go mod vendor
223228 - name : Check go licenses
224229 uses : aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8
225230 if : ${{ steps.check_languages.outputs.uses_go == 'true' }}
@@ -234,12 +239,17 @@ jobs:
234239 exit-code : " 1"
235240 list-all-pkgs : " false"
236241 trivy-config : trivy.yaml
242+ - name : clean go dependencies
243+ if : ${{ steps.check_languages.outputs.uses_go == 'true' }}
244+ run : |
245+ cd src
246+ rm -rf vendor
237247 - name : Check java licenses
238248 uses : aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8
239249 if : ${{ steps.check_languages.outputs.uses_java == 'true' }}
240250 with :
241251 scan-type : " fs"
242- skip-files : " **/poetry.lock,**/package-lock.json,**/go.sum "
252+ skip-files : " **/poetry.lock,**/package-lock.json,**/go.mod "
243253 scan-ref : " ."
244254 severity : " CRITICAL,HIGH"
245255 scanners : " license"
@@ -287,7 +297,7 @@ jobs:
287297 uses : aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8
288298 with :
289299 scan-type : " fs"
290- skip-files : " **/package-lock.json,**/go.sum ,**/pom.xml"
300+ skip-files : " **/package-lock.json,**/go.mod ,**/pom.xml"
291301 scan-ref : " ."
292302 severity : " CRITICAL,HIGH"
293303 scanners : " vuln"
@@ -300,7 +310,7 @@ jobs:
300310 uses : aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8
301311 with :
302312 scan-type : " fs"
303- skip-files : " **/poetry.lock,**/go.sum ,**/pom.xml"
313+ skip-files : " **/poetry.lock,**/go.mod ,**/pom.xml"
304314 scan-ref : " ."
305315 severity : " CRITICAL,HIGH"
306316 scanners : " vuln"
@@ -325,7 +335,7 @@ jobs:
325335 uses : aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8
326336 with :
327337 scan-type : " fs"
328- skip-files : " **/poetry.lock,**/package-lock.json,**/go.sum "
338+ skip-files : " **/poetry.lock,**/package-lock.json,**/go.mod "
329339 scan-ref : " ."
330340 severity : " CRITICAL,HIGH"
331341 scanners : " vuln"
0 commit comments