diff --git a/.github/workflows/analyze-changes.yaml b/.github/workflows/analyze-changes.yaml index 3a36cba0a62f..083b02658e45 100644 --- a/.github/workflows/analyze-changes.yaml +++ b/.github/workflows/analyze-changes.yaml @@ -131,6 +131,14 @@ jobs: cp -RP "${MVN_LOCAL_REPO}/com/datadoghq" ./workspace/.trivy/ ls -laR "./workspace/.trivy" + # NOTE: This avoids rate limits when pulling Trivy + - name: Login to GitHub Container Registry + uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0 + with: + registry: ghcr.io + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + - name: Run Trivy security scanner uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # v0.24.0 with: