Files
sec-actions/setup-db/README.md
T
t.behrendt f42efd6245
CI / Test Get Images From Files (pull_request) Successful in 4s
CI / Test scan-image (pull_request) Failing after 6s
CI / Test Setup DB (pull_request) Successful in 6s
CI / Test scan-config (pull_request) Failing after 12s
CI / Test Merge SARIF Files (pull_request) Successful in 23s
CI / Test scan-fs (pull_request) Failing after 1m2s
fix: ensure output dir exists
2026-04-10 19:16:33 +02:00

1.9 KiB

Setup DB Action

A reusable Gitea Action that sets up the Trivy vulnerability database, restoring from cache if available.

The action runs Trivy inside Docker with a restricted container configuration so the Trivy runtime is isolated from the host while the database is downloaded into your cache directory.

Note: This action only prepares the vulnerability database. If you run Trivy on the runner host for scans (for example trivy fs .), install Trivy separately (e.g. with a setup-trivy action or your own step).

Usage

Basic Usage

- name: Setup DB
  uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/setup-db@0.0.1

Complete Example

name: Security Scan
on: [push, pull_request]

jobs:
  security:
    runs-on:
      - ubuntu-latest
      - linux_amd64
    steps:
      - uses: actions/checkout@v4
      - name: Setup Trivy
        uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/setup-trivy@0.0.1
      - name: Setup DB
        uses: https://gitea.t000-n.de/t.behrendt/trivy-actions/setup-db@0.0.1
      - name: Scan for vulnerabilities
        run: trivy fs .

Inputs

Input Description Required Default
cache-dir Path to the Trivy cache directory No ${{ runner.temp }}/trivy
trivy-version Docker image reference for Trivy (digest pin recommended) No Pinned ghcr.io/aquasecurity/trivy image in action.yaml

trivy-version is optional. If you omit it, the action uses the default image (version and digest) from action.yaml. Set it only when you need a different Trivy image or your own digest pin.