Files
sec-actions/setup-trivy/action.yaml
T
renovate-bot 17b892e6b6
CD / Release (push) Successful in 12s
chore(deps): pin dependencies (#9)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/cache](https://github.com/actions/cache) | action | pinDigest |  -> `0057852` |
| [actions/checkout](https://github.com/actions/checkout) | action | pinDigest |  -> `08c6903` |

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xNTkuMyIsInVwZGF0ZWRJblZlciI6IjQxLjE1OS4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJhY3Rpb24iLCJkZXBzIl19-->

Reviewed-on: t.behrendt/trivy-actions#9
Reviewed-by: t.behrendt <t.behrendt@noreply.localhost>
Co-authored-by: Renovate Bot <renovate@t00n.de>
Co-committed-by: Renovate Bot <renovate@t00n.de>
2025-11-08 17:45:07 +01:00

79 lines
1.9 KiB
YAML

name: "Setup Trivy"
description: "Download and setup Trivy binary for vulnerability scanning"
author: "Gitea Actions"
branding:
icon: "shield"
color: "blue"
inputs:
version:
description: "Trivy version to download (e.g., v0.66.0)"
required: false
default: "v0.66.0"
architecture:
description: "System architecture (amd64, arm64)"
required: false
default: "amd64"
runs:
using: "composite"
steps:
- name: Cache Trivy binary
id: cache-trivy
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
with:
path: /usr/local/bin/trivy
key: trivy-${{ inputs.version }}-${{ inputs.architecture }}
restore-keys: |
trivy-${{ inputs.version }}-${{ inputs.architecture }}-
trivy-${{ inputs.version }}-
- name: Validate inputs
shell: bash
run: |
set -e
VERSION="${{ inputs.version }}"
ARCH="${{ inputs.architecture }}"
# Validate architecture
case "$ARCH" in
amd64|arm64)
;;
*)
echo "Error: Unsupported architecture '$ARCH'. Supported: amd64, arm64"
exit 1
;;
esac
- name: Download and install Trivy
if: steps.cache-trivy.outputs.cache-hit != 'true'
shell: bash
run: |
set -e
VERSION="${{ inputs.version }}"
ARCH="${{ inputs.architecture }}"
case "$ARCH" in
amd64)
ARCH="64bit"
;;
arm64)
ARCH="ARM64"
;;
esac
mkdir -p /usr/local/bin
curl -sL "https://github.com/aquasecurity/trivy/releases/download/${VERSION}/trivy_${VERSION#v}_Linux-${ARCH}.tar.gz" -o trivy.tar.gz
tar -xzf trivy.tar.gz
chmod +x trivy
mv trivy /usr/local/bin/
rm trivy.tar.gz
- name: Add Trivy to PATH
shell: bash
run: |
echo "/usr/local/bin" >> $GITHUB_PATH