Skip to content

Commit e0dc454

Browse files
committed
action: add trivy ci for image vulnerability scan
Signed-off-by: Yan Song <[email protected]>
1 parent 2fc62a6 commit e0dc454

File tree

1 file changed

+20
-0
lines changed

1 file changed

+20
-0
lines changed

.github/workflows/trivy.yml

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
name: CI
2+
3+
on:
4+
push:
5+
branches: ["*"]
6+
pull_request:
7+
branches: [main]
8+
9+
jobs:
10+
build:
11+
name: Trivy Scan
12+
runs-on: ubuntu-latest
13+
steps:
14+
- name: Install Trivy
15+
run: |
16+
wget https://github.com/aquasecurity/trivy/releases/download/v0.38.0/trivy_0.38.0_Linux-64bit.deb
17+
sudo dpkg -i trivy_0.18.3_Linux-64bit.deb
18+
- name: Scan Image
19+
run: |
20+
trivy image --timeout 60m ghcr.io/containerd/nydus-snapshotter:latest

0 commit comments

Comments
 (0)