Skip to content

Commit e151f61

Browse files
authored
CCM-15550: Disable Trivy in CI (#130)
1 parent e1fa889 commit e151f61

3 files changed

Lines changed: 33 additions & 31 deletions

File tree

.github/actions/trivy/action.yaml

Lines changed: 16 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,18 @@
1-
name: "Trivy Scan"
2-
runs:
3-
using: "composite"
4-
steps:
5-
- name: "Trivy Terraform IAC Scan"
6-
shell: bash
7-
run: |
8-
components_exit_code=0
9-
modules_exit_code=0
1+
#TODO - Re-visit Trivy usage https://nhsd-jira.digital.nhs.uk/browse/CCM-15549
2+
# name: "Trivy Scan"
3+
# runs:
4+
# using: "composite"
5+
# steps:
6+
# - name: "Trivy Terraform IAC Scan"
7+
# shell: bash
8+
# run: |
9+
# components_exit_code=0
10+
# modules_exit_code=0
1011

11-
./scripts/terraform/trivy.sh ./infrastructure/terraform/components || components_exit_code=$?
12-
./scripts/terraform/trivy.sh ./infrastructure/terraform/modules || modules_exit_code=$?
12+
# ./scripts/terraform/trivy.sh ./infrastructure/terraform/components || components_exit_code=$?
13+
# ./scripts/terraform/trivy.sh ./infrastructure/terraform/modules || modules_exit_code=$?
1314

14-
if [ $components_exit_code -ne 0 ] || [ $modules_exit_code -ne 0 ]; then
15-
echo "Trivy misconfigurations detected."
16-
exit 1
17-
fi
15+
# if [ $components_exit_code -ne 0 ] || [ $modules_exit_code -ne 0 ]; then
16+
# echo "Trivy misconfigurations detected."
17+
# exit 1
18+
# fi

.github/workflows/stage-1-commit.yaml

Lines changed: 16 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -148,21 +148,22 @@ jobs:
148148
uses: actions/checkout@v5
149149
- name: "Lint Terraform"
150150
uses: ./.github/actions/lint-terraform
151-
trivy:
152-
name: "Trivy Scan"
153-
runs-on: ubuntu-latest
154-
timeout-minutes: 5
155-
needs: detect-terraform-changes
156-
if: needs.detect-terraform-changes.outputs.terraform_changed == 'true'
157-
steps:
158-
- name: "Checkout code"
159-
uses: actions/checkout@v5
160-
- name: "Setup ASDF"
161-
uses: asdf-vm/actions/setup@v4
162-
- name: "Perform Setup"
163-
uses: ./.github/actions/setup
164-
- name: "Trivy Scan"
165-
uses: ./.github/actions/trivy
151+
#TODO - Re-visit Trivy usage https://nhsd-jira.digital.nhs.uk/browse/CCM-15549
152+
# trivy:
153+
# name: "Trivy Scan"
154+
# runs-on: ubuntu-latest
155+
# timeout-minutes: 5
156+
# needs: detect-terraform-changes
157+
# if: needs.detect-terraform-changes.outputs.terraform_changed == 'true'
158+
# steps:
159+
# - name: "Checkout code"
160+
# uses: actions/checkout@v5
161+
# - name: "Setup ASDF"
162+
# uses: asdf-vm/actions/setup@v4
163+
# - name: "Perform Setup"
164+
# uses: ./.github/actions/setup
165+
# - name: "Trivy Scan"
166+
# uses: ./.github/actions/trivy
166167
count-lines-of-code:
167168
name: "Count lines of code"
168169
runs-on: ubuntu-latest

.tool-versions

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,9 +5,9 @@ nodejs 22.12.0
55
pre-commit 3.6.0
66
terraform 1.9.2
77
terraform-docs 0.19.0
8-
trivy 0.61.0
98
vale 3.6.0
109
python 3.13.2
10+
# trivy 0.61.0 - TODO - Re-visit Trivy usage https://nhsd-jira.digital.nhs.uk/browse/CCM-15549
1111

1212
# ==============================================================================
1313
# The section below is reserved for Docker image versions.

0 commit comments

Comments
 (0)