diff --git a/.github/workflows/aquasec-scs-pr.yaml b/.github/workflows/aquasec-scs-pr.yaml index 6d3ab5f..e69d864 100644 --- a/.github/workflows/aquasec-scs-pr.yaml +++ b/.github/workflows/aquasec-scs-pr.yaml @@ -1,5 +1,10 @@ name: Aqua on: pull_request +env: + AQUA_KEY: ${{ secrets.AQUA_KEY }} + AQUA_SECRET: ${{ secrets.AQUA_SECRET }} + GITHUB_TOKEN: ${{ secrets.TOKEN }} + TRIVY_RUN_AS_PLUGIN: 'aqua' jobs: aqua: name: Aqua scanner @@ -16,9 +21,5 @@ jobs: # To enable SAST scanning, add: --sast # To enable reachability scanning, add: --reachability # To enable npm/dotnet/gradle non-lock file scanning, add: --package-json / --dotnet-proj / --gradle - env: - AQUA_KEY: ${{ secrets.AQUA_KEY }} - AQUA_SECRET: ${{ secrets.AQUA_SECRET }} - GITHUB_TOKEN: ${{ secrets.TOKEN }} - TRIVY_RUN_AS_PLUGIN: 'aqua' + # For http/https proxy configuration add env vars: HTTP_PROXY/HTTPS_PROXY, CA-CRET (path to CA certificate)