Skip to content

Trivy Scan

Trivy Scan #481

Workflow file for this run

name: Trivy Scan
on:
pull_request:
merge_group:
schedule:
- cron: "43 8 * * *"
workflow_dispatch:
permissions:
actions: read
contents: read
security-events: write
jobs:
trivy:
name: Trivy Filesystem Scan
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5
with:
persist-credentials: false
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@a9c7b0f06e461e9d4b4d1711f154ee024b8d7ab8
with:
scan-type: fs
scan-ref: .
format: sarif
output: trivy-results.sarif
severity: CRITICAL,HIGH
ignore-unfixed: true
exit-code: "0"
- name: Upload Trivy SARIF
if: ${{ !cancelled() && hashFiles('trivy-results.sarif') != '' }}
uses: github/codeql-action/upload-sarif@cdefb33c0f6224e58673d9004f47f7cb3e328b89
with:
sarif_file: trivy-results.sarif