-
Notifications
You must be signed in to change notification settings - Fork 278
Closed
Description
Since version 0.5.0 the timeout parameter seems to be ignored (we run into a timeout after 5 min)
Setup looks like this:
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@0.6.0
with:
image-ref: ${{ secrets.CONTAINER_REGISTRY }}/${{ inputs.image-package }}/${{ inputs.image-name }}:${{ env.IMAGE_VERSION }}
format: 'sarif'
output: 'trivy-results.sarif'
exit-code: '1'
ignore-unfixed: true
vuln-type: 'os'
security-checks: 'vuln'
severity: 'CRITICAL,HIGH'
timeout: '30m'
However, if we pass the timeout via yaml config, it works:
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@0.6.0
with:
image-ref: ${{ secrets.CONTAINER_REGISTRY }}/${{ inputs.image-package }}/${{ inputs.image-name }}:${{ env.IMAGE_VERSION }}
format: 'sarif'
...
trivy-config: ./trivy.yaml
trivy.yaml
timeout: 30m
jonpulsifer
Metadata
Metadata
Assignees
Labels
No labels