We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent fb92605 commit 9e4513aCopy full SHA for 9e4513a
.github/workflows/trivy-scan.yaml
@@ -0,0 +1,28 @@
1
+name: Trivy Security Scan
2
+on:
3
+ push:
4
+ branches: ["main"]
5
+ pull_request:
6
7
+
8
+jobs:
9
+ build:
10
+ name: build
11
+ runs-on: ubuntu-20.04
12
+ steps:
13
+ - name: Checkout code
14
+ uses: actions/checkout@v3
15
16
+ - name: Run Trivy vulnerability scanner
17
+ uses: aquasecurity/trivy-action@1f0aa582c8c8f5f7639610d6d38baddfea4fdcee # master
18
+ with:
19
+ scan-type: 'fs'
20
+ severity: 'CRITICAL,HIGH'
21
+ format: 'sarif'
22
+ output: 'trivy-results.sarif'
23
24
+ - name: Upload Trivy scan results to GitHub Security tab
25
+ uses: github/codeql-action/upload-sarif@16964e90ba004cdf0cd845b866b5df21038b7723 # v2.2.6
26
27
+ sarif_file: 'trivy-results.sarif'
28
+ category: 'code'
0 commit comments