Skip to content

Commit

Permalink
chore(workflow): add "Scan With Trivy and Upload Results to GitHub Se…
Browse files Browse the repository at this point in the history
…curity Tab"

Signed-off-by: Derek Su <[email protected]>
  • Loading branch information
derekbit committed Aug 31, 2024
1 parent 2cff860 commit 0565283
Showing 1 changed file with 34 additions and 0 deletions.
34 changes: 34 additions & 0 deletions .github/workflows/trivy-scan.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
name: Scan With Trivy and Upload Results to GitHub Security Tab

on:
workflow_dispatch:
push:
branches:
- master
- v*
pull_request:

jobs:
scan-vulnerabilities:
name: Scan for Vulnerabilities With Trivy
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4

- name: Run Trivy vulnerability scanner in fs mode
uses: aquasecurity/[email protected]
with:
scan-type: "fs"
scan-ref: "."
format: "sarif"
output: "trivy-results.sarif"
exit-code: "1"
ignore-unfixed: true
severity: "CRITICAL,HIGH"

- name: Upload Trivy Scan Results to GitHub Security Tab
if: failure()
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: "trivy-results.sarif"

0 comments on commit 0565283

Please sign in to comment.