8df2386e42
CD / Release (push) Successful in 11s
Using the "latest" released version of Trivy as the default version. We always first resolve latest to an actual version to allow the cache to work properly. Reviewed-on: t.behrendt/trivy-actions#15 Reviewed-by: branch-buddy <branch-buddy@t00n.de> Co-authored-by: Timo Behrendt <t.behrendt@t00n.de> Co-committed-by: Timo Behrendt <t.behrendt@t00n.de>
69 lines
1.9 KiB
YAML
69 lines
1.9 KiB
YAML
name: "Setup Trivy"
|
|
description: "Download and setup Trivy binary for vulnerability scanning"
|
|
author: "Gitea Actions"
|
|
branding:
|
|
icon: "shield"
|
|
color: "blue"
|
|
|
|
inputs:
|
|
version:
|
|
description: "Trivy version to download (e.g., latest)"
|
|
required: false
|
|
default: "latest"
|
|
|
|
runs:
|
|
using: "composite"
|
|
steps:
|
|
- shell: bash
|
|
id: arch
|
|
run: |
|
|
set -e
|
|
case "$(uname -m)" in
|
|
x86_64)
|
|
ARCH="64bit"
|
|
;;
|
|
aarch64)
|
|
ARCH="ARM64"
|
|
;;
|
|
esac
|
|
echo "ARCH=$ARCH" >> $GITHUB_OUTPUT
|
|
- name: Resolve version
|
|
shell: bash
|
|
id: version
|
|
run: |
|
|
set -e
|
|
if [ "${{ inputs.version }}" = "latest" ]; then
|
|
VERSION=$(curl -s https://api.github.com/repos/aquasecurity/trivy/releases/latest | jq -r '.tag_name')
|
|
else
|
|
VERSION="${{ inputs.version }}"
|
|
fi
|
|
echo "VERSION=$VERSION" >> $GITHUB_OUTPUT
|
|
- name: Cache Trivy binary
|
|
id: cache-trivy
|
|
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
|
|
with:
|
|
path: /usr/local/bin/trivy
|
|
key: trivy-${{ steps.version.outputs.version }}-${{ steps.arch.outputs.arch }}
|
|
restore-keys: |
|
|
trivy-${{ steps.version.outputs.version }}-${{ steps.arch.outputs.arch }}
|
|
- name: Download and install Trivy
|
|
if: steps.cache-trivy.outputs.cache-hit != 'true'
|
|
shell: bash
|
|
run: |
|
|
set -e
|
|
|
|
VERSION="${{ steps.version.outputs.version }}"
|
|
|
|
mkdir -p /usr/local/bin
|
|
|
|
curl -sL "https://github.com/aquasecurity/trivy/releases/download/${VERSION}/trivy_${VERSION#v}_Linux-${{ steps.arch.outputs.arch }}.tar.gz" -o trivy.tar.gz
|
|
tar -xzf trivy.tar.gz
|
|
chmod +x trivy
|
|
mv trivy /usr/local/bin/
|
|
rm trivy.tar.gz
|
|
|
|
- name: Add Trivy to PATH
|
|
shell: bash
|
|
run: |
|
|
echo "/usr/local/bin" >> $GITHUB_PATH
|