{"repo":"crazy-max/ghaction-container-scan","free":true,"listed":false,"github":"https://github.com/crazy-max/ghaction-container-scan","clone":"git clone https://github.com/crazy-max/ghaction-container-scan.git","description":"GitHub Action to check for vulnerabilities in your container image","language":"TypeScript","stars":74,"topics":["docker","github-actions","sarif-report","trivy","vulnerability-scanners","security-tools"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"About GitHub Action to check for vulnerabilities in your container image with Trivy. Usage Scan image Scan tarball Severity threshold GitHub annotations Upload to GitHub Code Scanning Build, scan and push your image Customizing inputs outputs Notes GITHUB TOKEN Minimum Permissions Advanced Security must be enabled for this repository to use code scanning failed to copy the image: write /tmp/fanal-2740541230: no space left on device timeout: context deadline exceeded could not parse reference: ghcr.io/UserName/myimage:latest Contributing License Usage Scan image Scan tarball Severity threshold You can define a threshold for severity to mark the job as failed: GitHub annotations This action is also able to create GitHub annotations in your workflow for vulnerabilities discovered: Upload to GitHub Code Scanning This action also supports the SARIF format for integration with GitHub Code Scanning to show issues in the GitHub Security tab: [!NOTE] dockerfile input is required to generate a sarif report. Build, scan and push your image Customizing inputs The following inputs can be used as step.with keys: Name Type Description ---------------------- -------- -------------------------------------------------------------------------------------------------- trivy version String Trivy CLI version (default latest ) image String Container image to scan (e.g. alpine:3.7 ) tarball String Container image tarball path to scan dockerfile String Dockerfile required to generate a sarif report s","default_branch":null,"files":null,"tree":[],"storefront":"/r/crazy-max","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/crazy-max/ghaction-container-scan/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}