From 97be2fedb1cc36a3c727834a3f79a213987279a2 Mon Sep 17 00:00:00 2001 From: Dan Alima Date: Sat, 30 Dec 2023 14:01:25 +0200 Subject: [PATCH] adding Docker scan with JFrog CLI --- .github/workflows/maven-build.yml | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/.github/workflows/maven-build.yml b/.github/workflows/maven-build.yml index 6e0bf3d17..4bfb76f84 100644 --- a/.github/workflows/maven-build.yml +++ b/.github/workflows/maven-build.yml @@ -40,4 +40,14 @@ jobs: - name: Set up JFrog CLI uses: jfrog/setup-jfrog-cli@v3 - name: Scan the project with your preferred SCA tool - run: jf --version \ No newline at end of file + run: jf docker scan docker.io/library/spring-petclinic:3.2.0-SNAPSHOT + - name: Login to Docker Hub + uses: docker/login-action@v3 + with: + username: ${{ secrets.DOCKERHUB_USERNAME }} + password: ${{ secrets.DOCKERHUB_TOKEN }} + - name: Build and push + uses: docker/build-push-action@v5 + with: + push: true + tags: user/app:latest