chore: fix security alerts (#1493)

https://github.com/project-zot/zot/security/code-scanning/4293

Signed-off-by: Ramkumar Chinchani <rchincha@cisco.com>
This commit is contained in:
Ramkumar Chinchani
2023-06-01 16:53:50 -07:00
committed by GitHub
parent 96d00cd0ef
commit d9e5f33e7e
7 changed files with 22 additions and 19 deletions
+4 -4
View File
@@ -10,10 +10,7 @@ on:
- published
name: build-test
permissions:
contents: read
packages: write
permissions: read-all
jobs:
build-test:
@@ -355,6 +352,9 @@ jobs:
if: github.event_name == 'release' && github.event.action== 'published'
needs: push-image
name: Update Helm Chart
permissions:
contents: write
packages: write
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
+2
View File
@@ -10,6 +10,8 @@ on:
branches:
- main
permissions: read-all
jobs:
check-commit-message-style:
name: Check commit message style
+2 -2
View File
@@ -23,7 +23,7 @@ jobs:
- name: Install dependencies
run: |
cd $GITHUB_WORKSPACE
go install github.com/swaggo/swag/cmd/swag
go install github.com/swaggo/swag/cmd/swag@v1.8.12
go mod download
sudo apt-get update
sudo apt-get install libgpgme-dev libassuan-dev libbtrfs-dev libdevmapper-dev pkg-config rpm uidmap
@@ -66,7 +66,7 @@ jobs:
- name: Install dependencies
run: |
cd $GITHUB_WORKSPACE
go install github.com/swaggo/swag/cmd/swag
go install github.com/swaggo/swag/cmd/swag@v1.8.12
go mod download
- name: Run sync harness
run: |
+7 -3
View File
@@ -7,13 +7,14 @@ on:
- main
workflow_dispatch:
permissions:
contents: read
packages: write
permissions: read-all
jobs:
sync-golang:
name: 'golang'
permissions:
contents: read
packages: write
strategy:
matrix:
golang_version:
@@ -34,6 +35,9 @@ jobs:
docker push ghcr.io/${{ github.repository_owner }}/golang:${{ matrix.golang_version }}
sync-trivy:
name: 'trivy-db'
permissions:
contents: read
packages: write
runs-on: ubuntu-latest
steps:
- name: Copy trivy-db using oras cli