From 0946c898b624cdf78e91cf83e8aef6d61cd78290 Mon Sep 17 00:00:00 2001 From: Timo Behrendt Date: Fri, 10 Apr 2026 18:02:08 +0200 Subject: [PATCH] feat: harden setup-db action --- setup-db/action.yaml | 23 ++++++++++++++++++++++- 1 file changed, 22 insertions(+), 1 deletion(-) diff --git a/setup-db/action.yaml b/setup-db/action.yaml index 889f3bd..8f4ac21 100644 --- a/setup-db/action.yaml +++ b/setup-db/action.yaml @@ -10,6 +10,10 @@ inputs: description: "Path to the Trivy cache directory (default: ${{runner.temp}}/trivy)" required: false default: "${{ runner.temp }}/trivy" + trivy-version: + description: "Trivy docker image version to use (full image reference including digest is recommended)" + required: false + default: "ghcr.io/aquasecurity/trivy:0.69.3@sha256:bcc376de8d77cfe086a917230e818dc9f8528e3c852f7b1aff648949b6258d1c" outputs: cache-dir: @@ -32,4 +36,21 @@ runs: trivy-db-${{ steps.current-date.outputs.current-date }} - if: steps.restore-db.outputs.cache-hit != 'true' shell: bash - run: trivy fs --download-db-only --cache-dir "${{ inputs.cache-dir }}" + run: | + docker run --rm \ + --name trivy-db-download \ + --user "$(id -u):$(id -g)" \ + --read-only \ + --env-file /dev/null \ + --cap-drop ALL \ + --pids-limit 64 \ + --memory=512m \ + --memory-swap=512m \ + --cpus=1 \ + --ipc private \ + --cgroupns private \ + --security-opt no-new-privileges \ + --security-opt apparmor=docker-default \ + --tmpfs /tmp:rw,noexec,nosuid,nodev,size=1g \ + --mount type=bind,src=${{ inputs.cache-dir }},dst=/cache \ + ${{ inputs.trivy-version }} fs --download-db-only --cache-dir /cache