name: "Setup Trivy" description: "Download and setup Trivy binary for vulnerability scanning" author: "Gitea Actions" branding: icon: "shield" color: "blue" inputs: version: description: "Trivy version to download (e.g., v0.57.1)" required: false default: "v0.57.1" architecture: description: "System architecture (amd64, arm64)" required: false default: "amd64" runs: using: "composite" steps: - name: Cache Trivy binary id: cache-trivy uses: actions/cache@v4 with: path: /usr/local/bin/trivy key: trivy-${{ inputs.version }}-${{ inputs.architecture }}-${{ hashFiles('**/action.yml') }} restore-keys: | trivy-${{ inputs.version }}-${{ inputs.architecture }}- trivy-${{ inputs.version }}- - name: Validate inputs shell: bash run: | set -e VERSION="${{ inputs.version }}" ARCH="${{ inputs.architecture }}" # Validate architecture case "$ARCH" in amd64|arm64) ;; *) echo "Error: Unsupported architecture '$ARCH'. Supported: amd64, arm64" exit 1 ;; esac - name: Download and install Trivy if: steps.cache-trivy.outputs.cache-hit != 'true' shell: bash run: | set -e VERSION="${{ inputs.version }}" ARCH="${{ inputs.architecture }}" case "$ARCH" in amd64) ARCH="64bit" ;; arm64) ARCH="ARM64" ;; esac mkdir -p /usr/local/bin curl -sL "https://github.com/aquasecurity/trivy/releases/download/${VERSION}/trivy_${VERSION#v}_Linux-${ARCH}.tar.gz" -o trivy.tar.gz tar -xzf trivy.tar.gz chmod +x trivy mv trivy /usr/local/bin/ rm trivy.tar.gz - name: Add Trivy to PATH shell: bash run: | echo "/usr/local/bin" >> $GITHUB_PATH - name: Verify Trivy installation shell: bash run: | trivy version