Skip to content

Commit 8578960

Browse files
committed
Added trivy action
1 parent d2b5bf7 commit 8578960

File tree

1 file changed

+35
-0
lines changed

1 file changed

+35
-0
lines changed
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
name: Trivy
2+
on:
3+
workflow_dispatch:
4+
push:
5+
branches: [ develop ]
6+
pull_request:
7+
branches: [ develop ]
8+
schedule:
9+
- cron: "0 8 * * 6"
10+
11+
jobs:
12+
ubuntu-php:
13+
name: PHP images vulnerability scanner
14+
runs-on: "ubuntu-18.04"
15+
strategy:
16+
matrix:
17+
php: ["5.6", "7.0", "7.2", "7.3", "7.4", "8.0"]
18+
steps:
19+
- name: Checkout
20+
uses: actions/checkout@v2
21+
22+
- name: Run Trivy vulnerability scanner
23+
uses: aquasecurity/trivy-action@master
24+
with:
25+
image-ref: 'docker.io/itkdev/php${{ matrix.php }}-fpm:latest'
26+
format: 'template'
27+
template: '@/contrib/sarif.tpl'
28+
output: 'trivy-results.sarif'
29+
severity: 'MEDIUM,CRITICAL,HIGH'
30+
ignore-unfixed: true
31+
32+
- name: Upload Trivy scan results to GitHub Security tab
33+
uses: github/codeql-action/upload-sarif@v1
34+
with:
35+
sarif_file: 'trivy-results.sarif'

0 commit comments

Comments
 (0)