We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
2 parents bb8fd95 + 33bd62e commit dacc524Copy full SHA for dacc524
.github/workflows/trivy.yml
@@ -0,0 +1,35 @@
1
+name: Trivy Security Scans
2
+
3
+on:
4
+ push:
5
+ branches: [ "master" ]
6
+ pull_request:
7
8
9
+ workflow_dispatch:
10
11
+jobs:
12
+ build:
13
+ name: build
14
+ runs-on: ubuntu-latest
15
+ steps:
16
+ - name: Checkout code
17
+ uses: actions/checkout@v3
18
19
+ - name: Run static analysis
20
+ uses: aquasecurity/trivy-action@master
21
+ with:
22
+ scan-type: 'fs'
23
+ vuln-type: 'library'
24
+ scanners: 'vuln,secret,config'
25
+ ignore-unfixed: true
26
+ format: 'sarif'
27
+ output: 'trivy-results.sarif'
28
+ severity: 'MEDIUM,HIGH,CRITICAL'
29
30
31
+ - name: Upload Trivy scan results to GitHub Security tab
32
+ uses: github/codeql-action/upload-sarif@v2
33
34
+ sarif_file: 'trivy-results.sarif'
35
+ category: 'code'
0 commit comments