fix(ci): keep trivy cache out of docker image

This commit is contained in:
jxxghp
2026-08-23 10:17:27 +08:00
parent 00bf7885c1
commit e16c28099b
4 changed files with 5 additions and 0 deletions
+1
View File
@@ -43,6 +43,7 @@ venv.bak/
.agent-work/
.runtime/
.tmp/
.cache/
node_modules/
public/
.moviepilot.env
+2
View File
@@ -161,6 +161,7 @@ jobs:
with:
image-ref: moviepilot-v3-candidate:linux-amd64
version: v0.70.0
cache-dir: ${{ runner.temp }}/trivy
scanners: vuln
vuln-type: os,library
severity: HIGH,CRITICAL
@@ -191,6 +192,7 @@ jobs:
with:
image-ref: moviepilot-v3-candidate:linux-arm64
version: v0.70.0
cache-dir: ${{ runner.temp }}/trivy
scanners: vuln
vuln-type: os,library
severity: HIGH,CRITICAL
+1
View File
@@ -25,6 +25,7 @@ def test_build_context_excludes_runtime_state_and_keeps_release_inputs() -> None
".agent-work/",
".runtime/",
".tmp/",
".cache/",
"node_modules/",
"public/",
".moviepilot.env",
+1
View File
@@ -76,6 +76,7 @@ def test_release_scans_both_architectures_before_registry_login_and_publish() ->
"Scan arm64 candidate vulnerabilities",
):
scan = indexed[name]
assert scan["with"]["cache-dir"] == "${{ runner.temp }}/trivy"
assert scan["uses"] == (
"aquasecurity/trivy-action@"
"a9c7b0f06e461e9d4b4d1711f154ee024b8d7ab8"