You can not select more than 25 topics
			Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
		
		
		
		
		
			
		
			
				
					
					
						
							42 lines
						
					
					
						
							1003 B
						
					
					
				
			
		
		
		
			
			
			
		
		
	
	
							42 lines
						
					
					
						
							1003 B
						
					
					
				| name: trivy | |
| 
 | |
| on: | |
|   push: | |
|     branches: | |
|       - main | |
|     tags: | |
|       - '*' | |
|   pull_request: | |
|     branches: [ "main" ] | |
|   schedule: | |
|     - cron: '00 12 * * *' | |
| 
 | |
| permissions: | |
|   contents: read | |
| 
 | |
| jobs: | |
|   trivy-scan: | |
|     name: Check | |
|     runs-on: ubuntu-22.04 | |
|     timeout-minutes: 30 | |
|     permissions: | |
|       contents: read | |
|       security-events: write | |
|       actions: read | |
|     steps: | |
|       - name: Checkout code | |
|         uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 #v4.1.1 | |
| 
 | |
|       - name: Run Trivy vulnerability scanner | |
|         uses: aquasecurity/trivy-action@2b6a709cf9c4025c5438138008beaddbb02086f0 # v0.14.0 | |
|         with: | |
|           scan-type: repo | |
|           ignore-unfixed: true | |
|           format: sarif | |
|           output: trivy-results.sarif | |
|           severity: CRITICAL,HIGH | |
| 
 | |
|       - name: Upload Trivy scan results to GitHub Security tab | |
|         uses: github/codeql-action/upload-sarif@bad341350a2f5616f9e048e51360cedc49181ce8 # v2.22.4 | |
|         with: | |
|           sarif_file: 'trivy-results.sarif'
 | |
| 
 |