Skip to content

trivy-image-scan

trivy-image-scan #1055

name: trivy-image-scan
on:
workflow_run:
workflows:
- build-image-dev
types:
- completed
schedule:
- cron: "0 */6 * * *"
env:
IMAGE_REPOSITORY: ${{ github.repository }}
REGISTRY: ghcr.io
jobs:
scan-image:
runs-on: ubuntu-latest
steps:
- name: Trivy image scan
uses: aquasecurity/trivy-action@master
with:
format: sarif
# ignore-unfixed: true
image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_REPOSITORY }}:latest
output: trivy-results.sarif
# severity: CRITICAL,HIGH
# vuln-type: os,library
- if: always()
name: Upload Trivy scan results
uses: github/codeql-action/upload-sarif@v2
with:
sarif_file: trivy-results.sarif