We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 23f04f0 commit eb20f0fCopy full SHA for eb20f0f
2 files changed
.github/workflows/quality-checks.yml
@@ -168,11 +168,11 @@ jobs:
168
echo "****************"
169
echo "uses_go=false" >> "$GITHUB_OUTPUT"
170
fi
171
- # Create trivy config to include dev dependencies
172
- cat <<EOF >> trivy.yaml
173
- pkg:
174
- include-dev-deps: true
175
- EOF
+ touch trivy.yaml
+ - name: Update trivy config to include dev dependencies
+ uses: mikefarah/yq@065b200af9851db0d5132f50bc10b1406ea5c0a8
+ with:
+ cmd: yq -i '.pkg.include-dev-deps = true' 'trivy.yaml'
176
- name: Check python licenses
177
uses: aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8
178
if: ${{ steps.check_languages.outputs.uses_poetry == 'true' }}
trivy.yaml
@@ -1,2 +1,2 @@
1
pkg:
2
+ include-dev-deps: false
0 commit comments