Skip to content

Commit dacc524

Browse files
authored
Merge pull request #148 from FHIR/do-20230828-trivy-check
Add trivy check
2 parents bb8fd95 + 33bd62e commit dacc524

File tree

1 file changed

+35
-0
lines changed

1 file changed

+35
-0
lines changed

.github/workflows/trivy.yml

+35
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
name: Trivy Security Scans
2+
3+
on:
4+
push:
5+
branches: [ "master" ]
6+
pull_request:
7+
branches: [ "master" ]
8+
9+
workflow_dispatch:
10+
11+
jobs:
12+
build:
13+
name: build
14+
runs-on: ubuntu-latest
15+
steps:
16+
- name: Checkout code
17+
uses: actions/checkout@v3
18+
19+
- name: Run static analysis
20+
uses: aquasecurity/trivy-action@master
21+
with:
22+
scan-type: 'fs'
23+
vuln-type: 'library'
24+
scanners: 'vuln,secret,config'
25+
ignore-unfixed: true
26+
format: 'sarif'
27+
output: 'trivy-results.sarif'
28+
severity: 'MEDIUM,HIGH,CRITICAL'
29+
30+
31+
- name: Upload Trivy scan results to GitHub Security tab
32+
uses: github/codeql-action/upload-sarif@v2
33+
with:
34+
sarif_file: 'trivy-results.sarif'
35+
category: 'code'

0 commit comments

Comments
 (0)