diff --git a/.github/workflows/common.yml b/.github/workflows/common.yml index c2b2b08b..a77e39be 100644 --- a/.github/workflows/common.yml +++ b/.github/workflows/common.yml @@ -21,7 +21,7 @@ on: enableSecurityScan: type: boolean required: false - default: false + default: true description: 'Enable security scan with Trivy' secrets: DOCKERHUB_USERNAME: @@ -40,6 +40,8 @@ env: VERBOSE: ${{ (github.debug || inputs.verbose) && 'true' || '' }} BRANCH: ${{ inputs.branch }} MAVEN_THREADS: ${{ inputs.mavenThreads }} + TRIVY_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-db,aquasec/trivy-db,ghcr.io/aquasecurity/trivy-db + TRIVY_JAVA_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-java-db,aquasec/trivy-java-db,ghcr.io/aquasecurity/trivy-java-db jobs: parameters: