I have 2 repo. Repo A, Repo B.
at Repo B, I include the yml file from Repo A.
include:
- project: 'test/A'
ref: master
file: '/.gitlab-ci.yml'
at the yml file of Repo A, it does wget file from Nexus Repo then extract it it to root
Trivy_container_scanning:
stage: test
image:
name: $CI_REGISTRY/devops/trivy/trivy:0.20.1
variables:
GIT_STRATEGY: none
IMAGE: "$CI_REGISTRY_IMAGE:$CI_COMMIT_SHA"
allow_failure: true
before_script:
- trivy image --reset
- git config --global http.sslVerify false
- git clone $CI_REPOSITORY_URL
- echo "the project directory is - $CI_PROJECT_DIR"
- echo "the registry image is - $CI_REGISTRY_IMAGE"
- ls -la
- trivy -h | grep cache
- mkdir -p /root/.cache/trivy/db
- ls -la
- wget "https://test.com/repository/klass_inst/devops/trivydb/trivy-offline.db.tgz" --no-check-certificate
- ls -la
- cp "trivy-offline.db.tgz" "/root/.cache/trivy/db"
- cd /root/.cache/trivy/db
- tar xvf trivy-offline.db.tgz
- ls -la
script:
- TRIVY_INSECURE=true trivy image --skip-update -f json -o "$CI_PROJECT_DIR/gl-container-scanning-report.json" $CI_REGISTRY/$IMAGE
artifacts:
reports:
container_scanning: gl-container-scanning-report.json
The pipeline job of Repo B complaints that copy failed.
actually I saw that the wget isn't happen. Below is the job log :
How do I handle such situation, I thought the wget will happend in Repo B runner.
$ mkdir -p /root/.cache/trivy/db
$ ls -la
total 0
drwxrwxrwx 3 root root 24 Oct 22 04:16 .
drwxrwxrwx 4 root root 46 Oct 22 04:16 ..
drwxr-xr-x 3 root root 75 Oct 22 04:16 eval-trivy
$ cp "trivy-scanner/trivy-offline.db.tgz" "/root/.cache/trivy/db"
cp: can't stat 'trivy-scanner/trivy-offline.db.tgz': No such file or directory