diff --git a/.github/workflows/devsecops.yaml b/.github/workflows/devsecops.yaml index fd042e6..1b6b0a0 100644 --- a/.github/workflows/devsecops.yaml +++ b/.github/workflows/devsecops.yaml @@ -137,7 +137,7 @@ jobs: # Running Trivy to scan the Docker image for vulnerabilities uses: aquasecurity/trivy-action@master with: - input: /github/workspace/image.tar + input: ./image.tar severity: "CRITICAL,HIGH" format: "sarif" output: "trivy-results.sarif"