Skip to content

Commit 6f6356f

Browse files
authored
Make the scanner to fail always with log4j vulnerability (#48)
1 parent 6386c09 commit 6f6356f

File tree

2 files changed

+6
-1
lines changed

2 files changed

+6
-1
lines changed

.github/workflows/build-scan-and-push.yaml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,7 @@ jobs:
2626
uses: docker/build-push-action@v3
2727
with:
2828
context: ${{ env.DOCKERFILE_CONTEXT }}
29+
file: "${{ env.DOCKERFILE_CONTEXT }}Dockerfile.log4j"
2930
tags: ${{ env.REGISTRY_HOST }}/${{ github.repository_owner }}/${{ env.IMAGE_NAME }}:${{ env.IMAGE_TAG }}
3031
load: true
3132

@@ -70,5 +71,6 @@ jobs:
7071
uses: docker/build-push-action@v3
7172
with:
7273
context: ${{ env.DOCKERFILE_CONTEXT }}
74+
file: "${{ env.DOCKERFILE_CONTEXT }}Dockerfile.log4j"
7375
push: true
74-
tags: ${{ env.REGISTRY_HOST }}/${{ github.repository_owner }}/${{ env.IMAGE_NAME }}:${{ env.IMAGE_TAG }}
76+
tags: ${{ env.REGISTRY_HOST }}/${{ github.repository_owner }}/${{ env.IMAGE_NAME }}:${{ env.IMAGE_TAG }}
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
FROM alpine:latest
2+
ADD https://archive.apache.org/dist/logging/log4j/2.14.1/apache-log4j-2.14.1-bin.tar.gz /root
3+
RUN tar xzvf /root/apache-log4j-2.14.1-bin.tar.gz

0 commit comments

Comments
 (0)