{"repo":"aquasecurity/trivy-action","free":true,"listed":false,"github":"https://github.com/aquasecurity/trivy-action","clone":"git clone https://github.com/aquasecurity/trivy-action.git","description":"Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities","language":"Shell","stars":1396,"topics":["devsecops","github-actions","scanning","security","tools","vulnerability","scanner"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Trivy Action GitHub Action for Trivy [![GitHub Release][release-img]][release] [![GitHub Marketplace][marketplace-img]][marketplace] [![License][license-img]][license] Table of Contents Usage Scan CI Pipeline Scan CI Pipeline (w/ Trivy Config) Cache Trivy Setup Scanning a Tarball Using Trivy with templates Using Trivy with GitHub Code Scanning Using Trivy to scan your Git repo Using Trivy to scan your rootfs directories Using Trivy to scan Infrastructure as Code Using Trivy to generate SBOM Using Trivy to scan your private registry Using Trivy if you don't have code scanning enabled Customizing inputs Environment variables Trivy config file Usage Scan CI Pipeline Scan CI Pipeline (w/ Trivy Config) In this case trivy.yaml is a YAML configuration that is checked in as part of the repo. Detailed information is available on the Trivy website but an example is as follows: It is possible to define all options in the trivy.yaml file. Specifying individual options via the action are left for backward compatibility purposes. Defining the following is required as they cannot be defined with the config file: - scan-ref : If using fs, repo scans. - image-ref : If using image scan. - scan-type : To define the scan type, e.g. image , fs , repo , etc. Order of preference for options Trivy uses Viper which has a defined precedence order for options. The order is as follows: - GitHub Action flag - Environment variable - Config file - Default Cache The action has a built-in functionality for c","default_branch":null,"files":null,"tree":[],"storefront":"/r/aquasecurity","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/aquasecurity/trivy-action/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}