Skip to content

Scanner-snyk-docker

Scanner-snyk-docker #1

name: Scanner-snyk-docker
permissions:
contents: read
on:
# pull_request:
# branchs: [ main ]
schedule:
- cron: '0 4 * * 0' # GMT time, 4:00 GMT == 12:00 China Every Sunday
workflow_dispatch:
inputs:
snyk_image:
description: 'snyk image'
required: true
type: string
default: 'intelanalytics/bigdl-k8s:latest'
snyk_tag:
description: 'snyk image tag'
required: true
type: string
default: 'latest'
jobs:
snyk-docker:
runs-on: [self-hosted, SDL-TEST]
steps:
- uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # actions/checkout@v3
- name: set env
run: |
echo "IMAGE=${{inputs.snyk_image}}"
- name: "Pull docker image"
run: |
# docker pull ${{inputs.snyk_image}}
- name: "snyk docker"
run: |
export IMAGE=intelanalytics/bigdl-k8s:latest
snyk monitor --docker $IMAGE