Added trivy to docker build, bumped alpine image

This commit is contained in:
Mike Farah 2020-12-21 15:48:25 +11:00
parent ca8cd78616
commit 6b17fd4fc1
2 changed files with 4 additions and 2 deletions

View File

@ -12,7 +12,7 @@ RUN CGO_ENABLED=0 make local build
# Choose alpine as a base image to make this useful for CI, as many
# CI tools expect an interactive shell inside the container
FROM alpine:3.12 as production
FROM alpine:3.12.3 as production
COPY --from=builder /go/src/mikefarah/yq/yq /usr/bin/yq
RUN chmod +x /usr/bin/yq

View File

@ -7,3 +7,5 @@ docker build \
-t mikefarah/yq:latest \
-t mikefarah/yq:${VERSION} \
.
trivy image mikefarah/yq:${VERSION}