From c392c910714644ac7f6638044a8b24d9ec535662 Mon Sep 17 00:00:00 2001 From: Ramkumar Chinchani <45800463+rchincha@users.noreply.github.com> Date: Sun, 12 Apr 2026 01:17:41 -0700 Subject: [PATCH] fix(ci): pass GITHUB_TOKEN explicitly to oras login in sync-trivy step (#3961) Signed-off-by: Ramkumar Chinchani --- .github/workflows/sync-3rdparty-images.yaml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/sync-3rdparty-images.yaml b/.github/workflows/sync-3rdparty-images.yaml index 41379917..abd7dc1e 100644 --- a/.github/workflows/sync-3rdparty-images.yaml +++ b/.github/workflows/sync-3rdparty-images.yaml @@ -47,11 +47,14 @@ jobs: sparse-checkout-cone-mode: false persist-credentials: false - name: Copy trivy-db using oras cli + env: + GHCR_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | # setup oras make $PWD/hack/tools/bin/oras export PATH=$PATH:$PWD/hack/tools/bin - echo "${GITHUB_TOKEN}" | oras login -u "${GITHUB_ACTOR}" --password-stdin ghcr.io + test -n "${GHCR_TOKEN}" || { echo "Missing GHCR token"; exit 1; } + echo "${GHCR_TOKEN}" | oras login -u "${GITHUB_ACTOR}" --password-stdin ghcr.io oras copy ghcr.io/aquasecurity/trivy-db:2 ghcr.io/${{ github.repository_owner }}/trivy-db:2 oras copy ghcr.io/aquasecurity/trivy-db:latest ghcr.io/${{ github.repository_owner }}/trivy-db:latest oras copy ghcr.io/aquasecurity/trivy-java-db:1 ghcr.io/${{ github.repository_owner }}/trivy-java-db:1