Files
sec-actions/get-images-from-files
t.behrendt 8ed8e7304c
CI / Test Setup Trivy amd64 (pull_request) Successful in 9s
CI / Test Setup DB (pull_request) Successful in 15s
CI / Test Get Images From Files (pull_request) Failing after 22s
CI / Test Setup Trivy arm64 (pull_request) Successful in 25s
docs: better list supported formats
2026-02-05 15:48:30 +01:00
..
2026-02-05 15:48:30 +01:00

Get Images From Files Action

A reusable Gitea Action that extracts Docker image references from selected files in a repository. Duplicate refs are deduplicated.

Note: Only fully-qualified refs (with registry, e.g. docker.io/library/alpine:latest, gcr.io/distroless/static:nonroot@sha256:...) are included; short refs like alpine:latest are omitted as their use is discouraged.

Supported file formats

Format How images are extracted
Dockerfile FROM lines; the image ref is the last token (handles FROM --platform=... <image>).
Kubernetes manifests Lines with image: (e.g. under containers / initContainers); the value is taken as the image ref.
Docker Compose / Compose Same as Kubernetes: image: key under services.
Helmfile values Pairs of repository and optional tag at the same indent; ref is repository or repository:tag. A lone tag without repository is skipped.

Other files are supported if they use one of these patterns (e.g. image: or FROM).

Usage

Basic Usage

- name: Get Images From Files
  uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/get-images-from-files@0.0.1
  with:
    files: |
        - Dockerfile
        - k8s/50_deployment.yaml
        - dockers/compose.yaml
        - values/traefik.yaml

Complete Example

name: Get Images From Files
on: [push, pull_request]

jobs:
  get-images-from-files:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - name: Get Images From Files
        uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/get-images-from-files@0.0.1
        with:
            files: |
              - Dockerfile
              - k8s/50_deployment.yaml
              - dockers/compose.yaml
              - values/traefik.yaml

Inputs

Input Description Required Default
files Files to extract images from. Multiple files can be specified.. Yes

Outputs

Output Description
images Comma separated list of extracted image references. Only fully-qualified refs (with registry, e.g. docker.io/library/alpine:latest, gcr.io/distroless/static:nonroot@sha256:...) are included; short refs like alpine:latest are omitted.