From 7616c45a9525dad6802b6da938e5a35c5a6d851b Mon Sep 17 00:00:00 2001 From: jacdavi <86626873+jacdavi@users.noreply.github.com> Date: Fri, 2 Oct 2026 15:15:44 -0700 Subject: [PATCH 1/2] fix(ci): correct issue where docker image on PR couldn't be scanned by storing locally --- .github/workflows/gws_image_build.yaml | 31 ++++++++++++++++++++++++- .github/workflows/m365_image_build.yaml | 25 +++++++++++++++++++- 2 files changed, 54 insertions(+), 2 deletions(-) diff --git a/.github/workflows/gws_image_build.yaml b/.github/workflows/gws_image_build.yaml index 6980596..e4bdf1a 100644 --- a/.github/workflows/gws_image_build.yaml +++ b/.github/workflows/gws_image_build.yaml @@ -79,6 +79,7 @@ jobs: type=schedule,pattern={{date 'YYYYMMDD'}} type=semver,pattern={{major}}.{{minor}} type=ref,event=branch + type=ref,event=pr # Build and push Docker image - name: Build and push @@ -87,9 +88,26 @@ jobs: with: context: gws/image push: ${{ github.event_name != 'pull_request' }} + load: ${{ github.event_name == 'pull_request' }} tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} - + + # Export image for scanning on PRs + - name: Export image + if: github.event_name == 'pull_request' + env: + IMAGE_REF: ${{ fromJSON(steps.meta.outputs.json).tags[0] }} + run: | + docker save "$IMAGE_REF" -o /tmp/image.tar + + - name: Upload image artifact + if: github.event_name == 'pull_request' + uses: actions/upload-artifact@v4 + with: + name: docker-image + path: /tmp/image.tar + retention-days: 1 + # Sign the resulting Docker image digest except on PRs. # This will only write to the public Rekor transparency log when the Docker # repository is public to avoid leaking data. If you would like to publish @@ -120,6 +138,17 @@ jobs: needs: build runs-on: ubuntu-latest steps: + - name: Download image artifact + if: github.event_name == 'pull_request' + uses: actions/download-artifact@v4 + with: + name: docker-image + path: /tmp + + - name: Load image + if: github.event_name == 'pull_request' + run: docker load -i /tmp/image.tar + - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@v0.36.0 with: diff --git a/.github/workflows/m365_image_build.yaml b/.github/workflows/m365_image_build.yaml index a428eee..b97ba76 100644 --- a/.github/workflows/m365_image_build.yaml +++ b/.github/workflows/m365_image_build.yaml @@ -79,6 +79,7 @@ jobs: type=schedule,pattern={{date 'YYYYMMDD'}} type=semver,pattern={{major}}.{{minor}} type=ref,event=branch + type=ref,event=pr # Build and push Docker image - name: Build and push Docker image @@ -88,6 +89,7 @@ jobs: LABELS: ${{ steps.meta.outputs.labels }} PUSH: ${{ github.event_name != 'pull_request' }} IMAGE: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} + IMAGE_REF: ${{ fromJSON(steps.meta.outputs.json).tags[0] }} shell: powershell run: | $docker_args = New-Object System.Collections.ArrayList @@ -105,9 +107,19 @@ jobs: echo "image=$($Env:IMAGE.ToLower())" >> $Env:GITHUB_OUTPUT if ($Env:PUSH -eq "true") { docker push $Env:IMAGE.ToLower() --all-tags + } else { + docker save $Env:IMAGE_REF -o image.tar } exit $LASTEXITCODE - + # Save the image as an artifact on PRs + - name: Upload image artifact + if: github.event_name == 'pull_request' + uses: actions/upload-artifact@v4 + with: + name: docker-image + path: image.tar + retention-days: 1 + # Sign the resulting Docker image digest except on PRs. # This will only write to the public Rekor transparency log when the Docker # repository is public to avoid leaking data. If you would like to publish @@ -138,6 +150,17 @@ jobs: needs: build runs-on: ubuntu-latest steps: + - name: Download image artifact + if: github.event_name == 'pull_request' + uses: actions/download-artifact@v4 + with: + name: docker-image + path: /tmp + + - name: Load image + if: github.event_name == 'pull_request' + run: docker load -i /tmp/image.tar + - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@v0.36.0 with: From e1f0ac6a316602a210b02742d623ce0afd3908eb Mon Sep 17 00:00:00 2001 From: jacdavi <86626873+jacdavi@users.noreply.github.com> Date: Fri, 2 Oct 2026 15:52:50 -0700 Subject: [PATCH 2/2] fix: handle scan of windows image on linux by reading tar directly --- .github/workflows/gws_image_build.yaml | 9 +++++++-- .github/workflows/m365_image_build.yaml | 9 +++++++-- 2 files changed, 14 insertions(+), 4 deletions(-) diff --git a/.github/workflows/gws_image_build.yaml b/.github/workflows/gws_image_build.yaml index e4bdf1a..984ed56 100644 --- a/.github/workflows/gws_image_build.yaml +++ b/.github/workflows/gws_image_build.yaml @@ -145,11 +145,16 @@ jobs: name: docker-image path: /tmp - - name: Load image + - name: Run Trivy vulnerability scanner on image archive if: github.event_name == 'pull_request' - run: docker load -i /tmp/image.tar + uses: aquasecurity/trivy-action@v0.36.0 + with: + input: /tmp/image.tar + format: 'sarif' + output: 'trivy-results.sarif' - name: Run Trivy vulnerability scanner + if: github.event_name != 'pull_request' uses: aquasecurity/trivy-action@v0.36.0 with: image-ref: ${{ needs.build.outputs.full-image }} diff --git a/.github/workflows/m365_image_build.yaml b/.github/workflows/m365_image_build.yaml index b97ba76..1496885 100644 --- a/.github/workflows/m365_image_build.yaml +++ b/.github/workflows/m365_image_build.yaml @@ -157,11 +157,16 @@ jobs: name: docker-image path: /tmp - - name: Load image + - name: Run Trivy vulnerability scanner on image archive if: github.event_name == 'pull_request' - run: docker load -i /tmp/image.tar + uses: aquasecurity/trivy-action@v0.36.0 + with: + input: /tmp/image.tar + format: 'sarif' + output: 'trivy-results.sarif' - name: Run Trivy vulnerability scanner + if: github.event_name != 'pull_request' uses: aquasecurity/trivy-action@v0.36.0 with: image-ref: ${{ needs.build.outputs.full-image }}