From 87571df3442fc2d94c4cd7881d6bccee4b5297bb Mon Sep 17 00:00:00 2001 From: Santiago Mola Date: Wed, 23 Oct 2024 14:24:05 +0200 Subject: [PATCH] Use docker login before Trivy action --- .github/workflows/analyze-changes.yaml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/.github/workflows/analyze-changes.yaml b/.github/workflows/analyze-changes.yaml index 3a36cba0a62f..083b02658e45 100644 --- a/.github/workflows/analyze-changes.yaml +++ b/.github/workflows/analyze-changes.yaml @@ -131,6 +131,14 @@ jobs: cp -RP "${MVN_LOCAL_REPO}/com/datadoghq" ./workspace/.trivy/ ls -laR "./workspace/.trivy" + # NOTE: This avoids rate limits when pulling Trivy + - name: Login to GitHub Container Registry + uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0 + with: + registry: ghcr.io + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + - name: Run Trivy security scanner uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # v0.24.0 with: