Skip to content

Commit 9011449

Browse files
authored
Merge pull request #1 from AmberJBlue/add-trivy-file-scan
Add trivy fs scan
2 parents d7de2ad + 9b72a17 commit 9011449

File tree

1 file changed

+48
-0
lines changed

1 file changed

+48
-0
lines changed
Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
name: Security Scan
2+
3+
on:
4+
push:
5+
branches: [main]
6+
pull_request:
7+
branches: [main]
8+
workflow_dispatch:
9+
10+
jobs:
11+
trivy-fs:
12+
name: Trivy FS
13+
runs-on: ubuntu-latest
14+
permissions:
15+
contents: read
16+
security-events: write
17+
18+
steps:
19+
- name: Checkout
20+
uses: actions/checkout@v4
21+
22+
- name: Run Trivy vulnerability scan
23+
uses: aquasecurity/[email protected]
24+
with:
25+
scan-type: fs
26+
scan-ref: .
27+
format: sarif
28+
output: trivy-results.sarif
29+
severity: CRITICAL,HIGH,MEDIUM,LOW
30+
exit-code: 0
31+
ignore-unfixed: false
32+
33+
- name: Check for critical and high vulnerabilities
34+
uses: aquasecurity/[email protected]
35+
with:
36+
scan-type: fs
37+
scan-ref: .
38+
format: table
39+
severity: CRITICAL,HIGH
40+
exit-code: 1
41+
ignore-unfixed: false
42+
43+
- name: Upload SARIF to Security tab
44+
if: always()
45+
uses: github/codeql-action/upload-sarif@v3
46+
with:
47+
sarif_file: trivy-results.sarif
48+
category: trivy-fs-security-scan

0 commit comments

Comments
 (0)