No description
Find a file
Kai Reichart 161bddc54b
Some checks failed
/ test_build_docker (push) Failing after 36s
added trivy scanning
2024-11-28 14:20:21 +01:00
.github/workflows added trivy scanning 2024-11-28 14:20:21 +01:00
README.md added trivy scanning 2024-11-28 14:20:21 +01:00

Run Trivy Image Scanner GitHub Action

This GitHub Action scans Docker images for vulnerabilities, secrets, licenses, and misconfigurations using Trivy.

Inputs

Input Name Description Required Type
image The Docker image to scan. Yes string

Usage

This action can be used in other workflows with workflow_call. Heres an example:

jobs:
  scan:
    uses:DevFW-CICD/vulnerability-scan/.github/workflows/trivy-image-scan.yml@main
    with:
      image: 'my-registry.com/project/image:latest'