diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index fa61d0c3..7ccfa454 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -42,6 +42,9 @@ jobs: needs: go-versions runs-on: ubuntu-latest name: "Trivy Scan of Docker Image" + env: + # Avoid rate-limiting on ghcr.io (https://github.com/aquasecurity/trivy-action/issues/389) + TRIVY_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-db:2 steps: - uses: actions/checkout@v4 with: diff --git a/.github/workflows/daily-security-scan-alpine.yml b/.github/workflows/daily-security-scan-alpine.yml index ead150ba..f2093212 100644 --- a/.github/workflows/daily-security-scan-alpine.yml +++ b/.github/workflows/daily-security-scan-alpine.yml @@ -14,6 +14,9 @@ jobs: steps: - uses: actions/checkout@v4 - uses: aquasecurity/trivy-action@master + env: + # Avoid rate-limiting on ghcr.io (https://github.com/aquasecurity/trivy-action/issues/389) + TRIVY_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-db:2 with: image-ref: launchdarkly/ld-relay:${{ matrix.tag }} format: 'table' diff --git a/.github/workflows/daily-security-scan-distroless.yml b/.github/workflows/daily-security-scan-distroless.yml index 9dbd131f..2fda4b65 100644 --- a/.github/workflows/daily-security-scan-distroless.yml +++ b/.github/workflows/daily-security-scan-distroless.yml @@ -14,6 +14,9 @@ jobs: steps: - uses: actions/checkout@v4 - uses: aquasecurity/trivy-action@master + env: + # Avoid rate-limiting on ghcr.io (https://github.com/aquasecurity/trivy-action/issues/389) + TRIVY_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-db:2 with: image-ref: launchdarkly/ld-relay:${{ matrix.tag }} format: 'table'