chore: remove setup-trivy action
CI / Test Setup Trivy amd64 (pull_request) Failing after 5s
CI / Test Merge SARIF Files (pull_request) Successful in 3s
CI / Test Setup DB (pull_request) Failing after 4s
CI / Test Get Images From Files (pull_request) Successful in 10s
CI / Test Setup Trivy arm64 (pull_request) Failing after 15s
CI / Test Setup Trivy amd64 (pull_request) Failing after 5s
CI / Test Merge SARIF Files (pull_request) Successful in 3s
CI / Test Setup DB (pull_request) Failing after 4s
CI / Test Get Images From Files (pull_request) Successful in 10s
CI / Test Setup Trivy arm64 (pull_request) Failing after 15s
This commit is contained in:
@@ -1,39 +0,0 @@
|
|||||||
# Setup Trivy Action
|
|
||||||
|
|
||||||
A reusable Gitea Action that downloads and sets up the Trivy binary for vulnerability scanning.
|
|
||||||
|
|
||||||
## Usage
|
|
||||||
|
|
||||||
### Basic Usage
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
- name: Setup Trivy
|
|
||||||
uses: your-username/trivy-actions@main/setup-trivy
|
|
||||||
with:
|
|
||||||
version: "v0.66.0" # Optional: Trivy version (default: latest)
|
|
||||||
```
|
|
||||||
|
|
||||||
### Complete Example
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
name: Security Scan
|
|
||||||
on: [push, pull_request]
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
security:
|
|
||||||
runs-on:
|
|
||||||
- ubuntu-latest
|
|
||||||
- linux_amd64
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
- name: Setup Trivy
|
|
||||||
uses: your-username/trivy-actions@main/setup-trivy
|
|
||||||
- name: Scan for vulnerabilities
|
|
||||||
run: trivy fs .
|
|
||||||
```
|
|
||||||
|
|
||||||
## Inputs
|
|
||||||
|
|
||||||
| Input | Description | Required | Default |
|
|
||||||
| --------- | ----------------------------------------- | -------- | -------- |
|
|
||||||
| `version` | Trivy version to download (e.g., v0.66.0) | No | `latest` |
|
|
||||||
@@ -1,68 +0,0 @@
|
|||||||
name: "Setup Trivy"
|
|
||||||
description: "Download and setup Trivy binary for vulnerability scanning"
|
|
||||||
author: "Gitea Actions"
|
|
||||||
branding:
|
|
||||||
icon: "shield"
|
|
||||||
color: "blue"
|
|
||||||
|
|
||||||
inputs:
|
|
||||||
version:
|
|
||||||
description: "Trivy version to download (e.g., latest)"
|
|
||||||
required: false
|
|
||||||
default: "latest"
|
|
||||||
|
|
||||||
runs:
|
|
||||||
using: "composite"
|
|
||||||
steps:
|
|
||||||
- shell: bash
|
|
||||||
id: arch
|
|
||||||
run: |
|
|
||||||
set -e
|
|
||||||
case "$(uname -m)" in
|
|
||||||
x86_64)
|
|
||||||
ARCH="64bit"
|
|
||||||
;;
|
|
||||||
aarch64)
|
|
||||||
ARCH="ARM64"
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
echo "ARCH=$ARCH" >> $GITHUB_OUTPUT
|
|
||||||
- name: Resolve version
|
|
||||||
shell: bash
|
|
||||||
id: version
|
|
||||||
run: |
|
|
||||||
set -e
|
|
||||||
if [ "${{ inputs.version }}" = "latest" ]; then
|
|
||||||
VERSION=$(curl -s https://api.github.com/repos/aquasecurity/trivy/releases/latest | jq -r '.tag_name')
|
|
||||||
else
|
|
||||||
VERSION="${{ inputs.version }}"
|
|
||||||
fi
|
|
||||||
echo "VERSION=$VERSION" >> $GITHUB_OUTPUT
|
|
||||||
- name: Cache Trivy binary
|
|
||||||
id: cache-trivy
|
|
||||||
uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5
|
|
||||||
with:
|
|
||||||
path: /usr/local/bin/trivy
|
|
||||||
key: trivy-${{ steps.version.outputs.version }}-${{ steps.arch.outputs.arch }}
|
|
||||||
restore-keys: |
|
|
||||||
trivy-${{ steps.version.outputs.version }}-${{ steps.arch.outputs.arch }}
|
|
||||||
- name: Download and install Trivy
|
|
||||||
if: steps.cache-trivy.outputs.cache-hit != 'true'
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
set -e
|
|
||||||
|
|
||||||
VERSION="${{ steps.version.outputs.version }}"
|
|
||||||
|
|
||||||
mkdir -p /usr/local/bin
|
|
||||||
|
|
||||||
curl -sL "https://github.com/aquasecurity/trivy/releases/download/${VERSION}/trivy_${VERSION#v}_Linux-${{ steps.arch.outputs.arch }}.tar.gz" -o trivy.tar.gz
|
|
||||||
tar -xzf trivy.tar.gz
|
|
||||||
chmod +x trivy
|
|
||||||
mv trivy /usr/local/bin/
|
|
||||||
rm trivy.tar.gz
|
|
||||||
|
|
||||||
- name: Add Trivy to PATH
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
echo "/usr/local/bin" >> $GITHUB_PATH
|
|
||||||
Reference in New Issue
Block a user