fix(ci): pin TRIVY_PLATFORM per matrix arch (post-#477 follow-up)
PR #477 moved Trivy from the merge-* job into the per-arch build-* matrix scanning by digest. The amd64 leg works; the arm64 leg crashes with: remote error: no child with platform linux/amd64 in index ghcr.io/.../<image>@sha256:<digest> Root cause: docker/build-push-action wraps every push in an OCI index — the actual image manifest sits next to a SLSA provenance attestation manifest as siblings under the digest. Trivy's remote backend defaults to linux/amd64 when resolving an index, so: - amd64 leg → looks for amd64 child → finds the amd64 image → ok. - arm64 leg → looks for amd64 child → finds NO amd64 child (the only platform child is arm64) → fails. Fix: set TRIVY_PLATFORM = ${{ matrix.platform }} on each leg's Trivy step. Each scanner then asks for its own arch and finds it. SLSA provenance attestation stays attached to the per-arch images — a real win for supply-chain visibility we'd lose if we'd disabled provenance instead. amd64 was the only thing keeping CI partly green; this restores full green across both legs without touching the build artifact shape.
This commit is contained in:
@@ -173,6 +173,17 @@ jobs:
|
|||||||
- name: Run Trivy vulnerability scanner (per-arch, by digest)
|
- name: Run Trivy vulnerability scanner (per-arch, by digest)
|
||||||
if: steps.push-decision.outputs.push == 'true'
|
if: steps.push-decision.outputs.push == 'true'
|
||||||
uses: aquasecurity/[email protected]
|
uses: aquasecurity/[email protected]
|
||||||
|
env:
|
||||||
|
# docker/build-push-action wraps every push in an OCI index
|
||||||
|
# (carries the SLSA provenance attestation alongside the
|
||||||
|
# actual image). Trivy's remote backend defaults to
|
||||||
|
# linux/amd64 regardless of host arch when resolving an
|
||||||
|
# index, which makes the arm64 leg crash with "no child
|
||||||
|
# with platform linux/amd64". Telling Trivy which child to
|
||||||
|
# scan keeps the provenance attestation intact and fixes
|
||||||
|
# the resolver crash. Pin to matrix.platform so each leg
|
||||||
|
# scans its own arch.
|
||||||
|
TRIVY_PLATFORM: ${{ matrix.platform }}
|
||||||
with:
|
with:
|
||||||
image-ref: ${{ env.REGISTRY }}/${{ env.BACKEND_IMAGE_NAME }}@${{ steps.build.outputs.digest }}
|
image-ref: ${{ env.REGISTRY }}/${{ env.BACKEND_IMAGE_NAME }}@${{ steps.build.outputs.digest }}
|
||||||
format: 'sarif'
|
format: 'sarif'
|
||||||
@@ -379,6 +390,12 @@ jobs:
|
|||||||
- name: Run Trivy vulnerability scanner (per-arch, by digest)
|
- name: Run Trivy vulnerability scanner (per-arch, by digest)
|
||||||
if: steps.push-decision.outputs.push == 'true'
|
if: steps.push-decision.outputs.push == 'true'
|
||||||
uses: aquasecurity/[email protected]
|
uses: aquasecurity/[email protected]
|
||||||
|
env:
|
||||||
|
# See build-backend for the rationale — pin Trivy's platform
|
||||||
|
# to the matrix arch so its remote-index resolver picks the
|
||||||
|
# right child instead of defaulting to linux/amd64 and
|
||||||
|
# crashing on the arm64 leg.
|
||||||
|
TRIVY_PLATFORM: ${{ matrix.platform }}
|
||||||
with:
|
with:
|
||||||
image-ref: ${{ env.REGISTRY }}/${{ env.FRONTEND_IMAGE_NAME }}@${{ steps.build.outputs.digest }}
|
image-ref: ${{ env.REGISTRY }}/${{ env.FRONTEND_IMAGE_NAME }}@${{ steps.build.outputs.digest }}
|
||||||
format: 'sarif'
|
format: 'sarif'
|
||||||
|
|||||||
Reference in New Issue
Block a user