Skip to content

scan

scan #821

name: scan
on:
schedule:
- cron: "0 8 * * *"
# Declare default permissions as read only.
permissions: read-all
jobs:
scan:
name: Scan
runs-on: ubuntu-22.04
permissions:
security-events: write
steps:
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@d43c1f16c00cfd3978dde6c07f4bbcf9eb6993ca # 0.16.1
with:
image-ref: "ghcr.io/${{ github.repository }}:latest"
format: "sarif"
output: "trivy-results.sarif"
severity: "CRITICAL,HIGH"
- name: Upload Trivy scan results to GitHub Security tab
uses: github/codeql-action/upload-sarif@e5f05b81d5b6ff8cfa111c80c22c5fd02a384118 # v3
if: always()
with:
sarif_file: "trivy-results.sarif"