From f7ecf84dfea311e1871745d49d471ce632a359df Mon Sep 17 00:00:00 2001 From: Timo Behrendt Date: Sat, 8 Nov 2025 19:22:30 +0100 Subject: [PATCH] feat(setup-trivy)!: automatically determine arch (#14) Mapping x86_64 to "64bit" and aarch64 to "ARM64" as this is how Trivy names their releases. Adjusted CICD to test-run both amd64 and arm64 versions. Reviewed-on: https://gitea.t000-n.de/t.behrendt/trivy-actions/pulls/14 Reviewed-by: branch-buddy Co-authored-by: Timo Behrendt Co-committed-by: Timo Behrendt --- .gitea/workflows/ci.yaml | 10 ++++---- setup-db/README.md | 1 - setup-trivy/README.md | 9 +++---- setup-trivy/action.yaml | 55 +++++++++++++--------------------------- 4 files changed, 25 insertions(+), 50 deletions(-) diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index e37790c..aae5763 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -5,17 +5,19 @@ on: jobs: test-setup-trivy: - name: Test Setup Trivy + strategy: + matrix: + arch: [amd64, arm64] + name: Test Setup Trivy ${{ matrix.arch }} runs-on: - ubuntu-latest - - linux_amd64 + - linux_${{ matrix.arch }} steps: - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5 - name: Setup Trivy uses: ./setup-trivy with: version: v0.66.0 - architecture: amd64 - name: Run Trivy run: trivy --version @@ -23,13 +25,11 @@ jobs: name: Test Setup DB runs-on: - ubuntu-latest - - linux_amd64 steps: - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5 - uses: ./setup-trivy with: version: v0.66.0 - architecture: amd64 - name: Setup DB uses: ./setup-db with: diff --git a/setup-db/README.md b/setup-db/README.md index 0f658f3..b765a7a 100644 --- a/setup-db/README.md +++ b/setup-db/README.md @@ -30,7 +30,6 @@ jobs: uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/setup-trivy@0.0.1 with: version: "v0.66.0" - architecture: "amd64" - name: Setup DB uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/setup-db@0.0.1 - name: Scan for vulnerabilities diff --git a/setup-trivy/README.md b/setup-trivy/README.md index ef04950..6835c39 100644 --- a/setup-trivy/README.md +++ b/setup-trivy/README.md @@ -11,7 +11,6 @@ A reusable Gitea Action that downloads and sets up the Trivy binary for vulnerab uses: your-username/trivy-actions@main/setup-trivy with: version: "v0.66.0" # Optional: Trivy version (default: v0.66.0) - architecture: "amd64" # Optional: amd64 or arm64 (default: amd64) ``` ### Complete Example @@ -31,14 +30,12 @@ jobs: uses: your-username/trivy-actions@main/setup-trivy with: version: "v0.66.0" - architecture: "amd64" - name: Scan for vulnerabilities run: trivy fs . ``` ## Inputs -| Input | Description | Required | Default | -| -------------- | ----------------------------------------- | -------- | --------- | -| `version` | Trivy version to download (e.g., v0.66.0) | No | `v0.66.0` | -| `architecture` | System architecture (amd64, arm64) | No | `amd64` | +| Input | Description | Required | Default | +| --------- | ----------------------------------------- | -------- | --------- | +| `version` | Trivy version to download (e.g., v0.66.0) | No | `v0.66.0` | diff --git a/setup-trivy/action.yaml b/setup-trivy/action.yaml index a9f18af..745583f 100644 --- a/setup-trivy/action.yaml +++ b/setup-trivy/action.yaml @@ -7,45 +7,34 @@ branding: inputs: version: - description: "Trivy version to download (e.g., v0.66.0)" + description: "Trivy version to download (e.g., latest)" required: false default: "v0.66.0" - architecture: - description: "System architecture (amd64, arm64)" - required: false - default: "amd64" runs: using: "composite" steps: + - shell: bash + id: arch + run: | + set -e + case "$(uname -m)" in + x86_64) + ARCH="64bit" + ;; + aarch64) + ARCH="ARM64" + ;; + esac + echo "ARCH=$ARCH" >> $GITHUB_OUTPUT - name: Cache Trivy binary id: cache-trivy uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4 with: path: /usr/local/bin/trivy - key: trivy-${{ inputs.version }}-${{ inputs.architecture }} + key: trivy-${{ inputs.version }}-${{ steps.arch.outputs.arch }} restore-keys: | - trivy-${{ inputs.version }}-${{ inputs.architecture }}- - trivy-${{ inputs.version }}- - - - name: Validate inputs - shell: bash - run: | - set -e - - VERSION="${{ inputs.version }}" - ARCH="${{ inputs.architecture }}" - - # Validate architecture - case "$ARCH" in - amd64|arm64) - ;; - *) - echo "Error: Unsupported architecture '$ARCH'. Supported: amd64, arm64" - exit 1 - ;; - esac - + trivy-${{ inputs.version }}-${{ steps.arch.outputs.arch }} - name: Download and install Trivy if: steps.cache-trivy.outputs.cache-hit != 'true' shell: bash @@ -53,20 +42,10 @@ runs: set -e VERSION="${{ inputs.version }}" - ARCH="${{ inputs.architecture }}" - - case "$ARCH" in - amd64) - ARCH="64bit" - ;; - arm64) - ARCH="ARM64" - ;; - esac mkdir -p /usr/local/bin - curl -sL "https://github.com/aquasecurity/trivy/releases/download/${VERSION}/trivy_${VERSION#v}_Linux-${ARCH}.tar.gz" -o trivy.tar.gz + curl -sL "https://github.com/aquasecurity/trivy/releases/download/${VERSION}/trivy_${VERSION#v}_Linux-${{ steps.arch.outputs.arch }}.tar.gz" -o trivy.tar.gz tar -xzf trivy.tar.gz chmod +x trivy mv trivy /usr/local/bin/