Files
sec-actions/setup-db/README.md
T
t.behrendt efef29591b
CI / Test Get Images From Files (pull_request) Successful in 4s
CI / Test Setup Trivy amd64 (pull_request) Successful in 5s
CI / Test Merge SARIF Files (pull_request) Successful in 5s
CI / Test Setup Trivy arm64 (pull_request) Successful in 39s
CI / Test Setup DB (pull_request) Successful in 1m12s
feat: harden setup-db action
2026-04-10 18:34:01 +02:00

1.8 KiB

Setup DB Action

A reusable Gitea Action that sets up the Trivy vulnerability database, restoring from cache if available.

The action runs Trivy inside Docker with a restricted container configuration so the Trivy runtime is isolated from the host while the database is downloaded into your cache directory.

Note: This action only prepares the vulnerability database. If you run Trivy on the runner host for scans (for example trivy fs .), install Trivy separately (e.g. with a setup-trivy action or your own step).

Usage

Basic Usage

- name: Setup DB
  uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/setup-db@0.0.1

Complete Example

name: Security Scan
on: [push, pull_request]

jobs:
  security:
    runs-on:
      - ubuntu-latest
      - linux_amd64
    steps:
      - uses: actions/checkout@v4
      - name: Setup Trivy
        uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/setup-trivy@0.0.1
      - name: Setup DB
        uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/setup-db@0.0.1
      - name: Scan for vulnerabilities
        run: trivy fs .

Inputs

Input Description Required Default
cache-dir Path to the Trivy cache directory No ${{ runner.temp }}/trivy
trivy-version Docker image reference for Trivy (digest pin recommended) No Pinned ghcr.io/aquasecurity/trivy image in action.yaml

trivy-version is optional. If you omit it, the action uses the default image (version and digest) from action.yaml. Set it only when you need a different Trivy image or your own digest pin.