From 5eaa9882dac8c7cc7c9bbc537cf1866ae7b30fcd Mon Sep 17 00:00:00 2001 From: Santiago Mola Date: Wed, 23 Oct 2024 14:21:29 +0200 Subject: [PATCH] Use docker login before Trivy action --- .github/workflows/analyze-changes.yaml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/.github/workflows/analyze-changes.yaml b/.github/workflows/analyze-changes.yaml index 3a36cba0a62..083b02658e4 100644 --- a/.github/workflows/analyze-changes.yaml +++ b/.github/workflows/analyze-changes.yaml @@ -131,6 +131,14 @@ jobs: cp -RP "${MVN_LOCAL_REPO}/com/datadoghq" ./workspace/.trivy/ ls -laR "./workspace/.trivy" + # NOTE: This avoids rate limits when pulling Trivy + - name: Login to GitHub Container Registry + uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0 + with: + registry: ghcr.io + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + - name: Run Trivy security scanner uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # v0.24.0 with: