81eda53a59
CD / Release (push) Successful in 4s
As part of our safety initiative, I'm refactoring setup-db to run trivy inside a Docker container with minimal privileges, reducing leakage of secrets, files, etc. to a minimum in case the dependency gets compromised. Additionally, we are always pinning the trivy docker image to a fixed digest. Renovate has been configured to keep the Trivy image version up-to-date. Reviewed-on: #54 Reviewed-by: branch-buddy <branch-buddy@t00n.de> Co-authored-by: Timo Behrendt <t.behrendt@t00n.de> Co-committed-by: Timo Behrendt <t.behrendt@t00n.de>
1.8 KiB
1.8 KiB
Setup DB Action
A reusable Gitea Action that sets up the Trivy vulnerability database, restoring from cache if available.
The action runs Trivy inside Docker with a restricted container configuration so the Trivy runtime is isolated from the host while the database is downloaded into your cache directory.
Note: This action only prepares the vulnerability database. If you run Trivy on the runner host for scans (for example trivy fs .), install Trivy separately (e.g. with a setup-trivy action or your own step).
Usage
Basic Usage
- name: Setup DB
uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/setup-db@0.0.1
Complete Example
name: Security Scan
on: [push, pull_request]
jobs:
security:
runs-on:
- ubuntu-latest
- linux_amd64
steps:
- uses: actions/checkout@v4
- name: Setup Trivy
uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/setup-trivy@0.0.1
- name: Setup DB
uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/setup-db@0.0.1
- name: Scan for vulnerabilities
run: trivy fs .
Inputs
| Input | Description | Required | Default |
|---|---|---|---|
cache-dir |
Path to the Trivy cache directory | No | ${{ runner.temp }}/trivy |
trivy-version |
Docker image reference for Trivy (digest pin recommended) | No | Pinned ghcr.io/aquasecurity/trivy image in action.yaml |
trivy-version is optional. If you omit it, the action uses the default image (version and digest) from action.yaml. Set it only when you need a different Trivy image or your own digest pin.