From 16a892b3a73a1c6bc3fca0baeb9c738e7fa281d8 Mon Sep 17 00:00:00 2001 From: Bo-Yi Wu Date: Thu, 16 Apr 2026 23:01:13 +0800 Subject: [PATCH] ci(docker): fail push when trivy finds CRITICAL/HIGH issues --- .github/workflows/docker.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 791cae4..7f2d930 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -82,7 +82,7 @@ jobs: format: "sarif" output: "trivy-image-results.sarif" severity: "CRITICAL,HIGH" - + exit-code: '1' - name: Upload Trivy scan results to GitHub Security tab uses: github/codeql-action/upload-sarif@v4 if: always()