diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 3a8758f..9fddd6b 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -49,10 +49,9 @@ jobs: uses: aquasecurity/trivy-action@master with: image-ref: ${{ env.imageName }}:${{ steps.docker_meta.outputs.version }} - format: "template" - template: "@/contrib/sarif.tpl" + format: "sarif" output: "trivy-results.sarif" - name: Upload Trivy scan results to GitHub Security tab - uses: github/codeql-action/upload-sarif@v1 + uses: github/codeql-action/upload-sarif@v2 with: sarif_file: "trivy-results.sarif"