efef29591b
CI / Test Get Images From Files (pull_request) Successful in 4s
CI / Test Setup Trivy amd64 (pull_request) Successful in 5s
CI / Test Merge SARIF Files (pull_request) Successful in 5s
CI / Test Setup Trivy arm64 (pull_request) Successful in 39s
CI / Test Setup DB (pull_request) Successful in 1m12s
47 lines
1.8 KiB
Markdown
47 lines
1.8 KiB
Markdown
# Setup DB Action
|
|
|
|
A reusable Gitea Action that sets up the Trivy vulnerability database, restoring from cache if available.
|
|
|
|
The action runs Trivy inside **Docker** with a restricted container configuration so the Trivy runtime is isolated from the host while the database is downloaded into your cache directory.
|
|
|
|
**Note:** This action only prepares the vulnerability database. If you run Trivy on the runner host for scans (for example `trivy fs .`), install Trivy separately (e.g. with a `setup-trivy` action or your own step).
|
|
|
|
## Usage
|
|
|
|
### Basic Usage
|
|
|
|
```yaml
|
|
- name: Setup DB
|
|
uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/setup-db@0.0.1
|
|
```
|
|
|
|
### Complete Example
|
|
|
|
```yaml
|
|
name: Security Scan
|
|
on: [push, pull_request]
|
|
|
|
jobs:
|
|
security:
|
|
runs-on:
|
|
- ubuntu-latest
|
|
- linux_amd64
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Setup Trivy
|
|
uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/setup-trivy@0.0.1
|
|
- name: Setup DB
|
|
uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/setup-db@0.0.1
|
|
- name: Scan for vulnerabilities
|
|
run: trivy fs .
|
|
```
|
|
|
|
## Inputs
|
|
|
|
| Input | Description | Required | Default |
|
|
| ---------------- | --------------------------------------------------------------------------- | -------- | ------- |
|
|
| `cache-dir` | Path to the Trivy cache directory | No | `${{ runner.temp }}/trivy` |
|
|
| `trivy-version` | Docker image reference for Trivy (digest pin recommended) | No | Pinned `ghcr.io/aquasecurity/trivy` image in `action.yaml` |
|
|
|
|
**`trivy-version` is optional.** If you omit it, the action uses the default image (version and digest) from `action.yaml`. Set it only when you need a different Trivy image or your own digest pin.
|