Files
sec-actions/get-images-from-files
t.behrendt 19cf9c7dd6
CI / Test Setup Trivy amd64 (pull_request) Successful in 9s
CI / Test Setup DB (pull_request) Successful in 15s
CI / Test Get Images From Files (pull_request) Successful in 21s
CI / Test Setup Trivy arm64 (pull_request) Successful in 24s
refactor: remove handling of sole repository, always require both repo and tag
2026-02-05 17:15:14 +01:00
..

Get Images From Files Action

A reusable Gitea Action that extracts Docker image references from selected files in a repository. Duplicate refs are deduplicated.

Note: Only fully-qualified refs (with registry, e.g. docker.io/library/alpine:latest, gcr.io/distroless/static:nonroot@sha256:...) are included; short refs like alpine:latest are omitted as their use is discouraged.

Supported file formats

Format How images are extracted
Dockerfile FROM lines; the image ref is the last token (handles FROM --platform=... <image>).
Kubernetes manifests Lines with image: (e.g. under containers / initContainers); the value is taken as the image ref.
Docker Compose / Compose Same as Kubernetes: image: key under services.
Helmfile values Pairs of repository and tag (both required) at the same indent; ref is repository:tag. A lone tag without repository is skipped.

Other files are supported if they use one of these patterns (e.g. image: or FROM).

Usage

Basic Usage

- name: Get Images From Files
  uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/get-images-from-files@0.0.1
  with:
    files: |
        - Dockerfile
        - k8s/50_deployment.yaml
        - dockers/compose.yaml
        - values/traefik.yaml

Complete Example

name: Get Images From Files
on: [push, pull_request]

jobs:
  get-images-from-files:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - name: Get Images From Files
        uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/get-images-from-files@0.0.1
        with:
            files: |
              - Dockerfile
              - k8s/50_deployment.yaml
              - dockers/compose.yaml
              - values/traefik.yaml

Inputs

Input Description Required Default
files Files to extract images from. Multiple files can be specified.. Yes

Outputs

Output Description
images Comma separated list of extracted image references. Only fully-qualified refs (with registry, e.g. docker.io/library/alpine:latest, gcr.io/distroless/static:nonroot@sha256:...) are included; short refs like alpine:latest are omitted.