feat: make trivy scan cause build to fail configurable

This commit is contained in:
Stefan Reimer 2022-02-14 12:52:49 +01:00
parent a4c2a55289
commit 5823b8b0a7

View File

@ -49,7 +49,7 @@ def call(Map config) {
] ]
// Scan again and fail on CRITICAL vulns // Scan again and fail on CRITICAL vulns
sh 'TRIVY_EXIT_CODE=1 TRIVY_SEVERITY=CRITICAL make scan' sh '[ "${config.trivyFail}" == "NONE" ] || TRIVY_EXIT_CODE=1 TRIVY_SEVERITY=${config.trivyFail} make scan'
} }
} }