diff --git a/Dockerfile b/Dockerfile index 3e54990..3723a67 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,3 +1,3 @@ -FROM lacework/lacework-inline-scanner:0.23.2 +FROM lacework/lacework-inline-scanner:0.27.0 COPY ./docker-entrypoint.sh / ENTRYPOINT ["/docker-entrypoint.sh"] diff --git a/docker-entrypoint.sh b/docker-entrypoint.sh index 495bc4b..7f8763b 100755 --- a/docker-entrypoint.sh +++ b/docker-entrypoint.sh @@ -41,12 +41,12 @@ fi # Remove old scanner evaluation, if cached somehow rm ${GITHUB_WORKSPACE}/evaluations/${INPUT_IMAGE_NAME}/${INPUT_IMAGE_TAG}/evaluation_*.json &>/dev/null || true -/opt/lacework/lw-scanner image evaluate ${INPUT_IMAGE_NAME} ${INPUT_IMAGE_TAG} \ +/app/vulnerability/scanner/lacework/local-scanner/main/local-scanner.binary image evaluate ${INPUT_IMAGE_NAME} ${INPUT_IMAGE_TAG} \ --build-plan ${GITHUB_REPOSITORY} \ --build-id ${GITHUB_RUN_ID} \ --data-directory ${GITHUB_WORKSPACE} \ --policy \ - --fail-on-violation-exit-code 1 ${SCANNER_PARAMETERS} | tee results.stdout + --fail-on-violation-exit-code 1 ${SCANNER_PARAMETERS} > results.stdout export SCANNER_EXIT_CODE=$? @@ -57,4 +57,4 @@ if [ "${INPUT_RESULTS_IN_GITHUB_SUMMARY}" = "true" ]; then echo "" >> $GITHUB_STEP_SUMMARY fi -exit ${SCANNER_EXIT_CODE} \ No newline at end of file +exit ${SCANNER_EXIT_CODE}