Decided to remove the stupid double scan
This commit is contained in:
@@ -23,7 +23,7 @@ if [ -z "$INPUT_IMAGE_NAME" ]; then
|
|||||||
exit 1
|
exit 1
|
||||||
fi;
|
fi;
|
||||||
|
|
||||||
GRYPE_OPTIONS=("-v" "--by-cve")
|
GRYPE_OPTIONS=("-v" "--by-cve" "--show-suppressed")
|
||||||
|
|
||||||
if [ -n "$INPUT_CONFIG_PATH" ] && [ -f "$INPUT_CONFIG_PATH" ]; then
|
if [ -n "$INPUT_CONFIG_PATH" ] && [ -f "$INPUT_CONFIG_PATH" ]; then
|
||||||
GRYPE_OPTIONS+=("--config" "$INPUT_CONFIG_PATH")
|
GRYPE_OPTIONS+=("--config" "$INPUT_CONFIG_PATH")
|
||||||
@@ -40,10 +40,6 @@ else
|
|||||||
GRYPE_OPTIONS+=("file:${INPUT_IMAGE_NAME}")
|
GRYPE_OPTIONS+=("file:${INPUT_IMAGE_NAME}")
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# shellcheck disable=SC2145
|
|
||||||
echo "Running grype container scanning with options: ${GRYPE_OPTIONS[@]} --show-suppressed"
|
|
||||||
grype "${GRYPE_OPTIONS[@]}" "--show-suppressed"
|
|
||||||
|
|
||||||
if [ -n "$INPUT_FAIL_ON" ]; then
|
if [ -n "$INPUT_FAIL_ON" ]; then
|
||||||
GRYPE_OPTIONS+=("--fail-on" "$INPUT_FAIL_ON")
|
GRYPE_OPTIONS+=("--fail-on" "$INPUT_FAIL_ON")
|
||||||
fi
|
fi
|
||||||
|
|||||||
Reference in New Issue
Block a user