diff --git a/.github/workflows/trivy.yml b/.github/workflows/trivy.yml new file mode 100644 index 0000000..842679c --- /dev/null +++ b/.github/workflows/trivy.yml @@ -0,0 +1,50 @@ +name: Trivy Security Scan + +on: + schedule: + # Run at 00:00 on day 1 of every 3rd month (January, April, July, October) + - cron: "0 0 1 */3 *" + workflow_dispatch: # Allow manual trigger + push: + branches: + - master + pull_request: + branches: + - master + +permissions: + contents: read + security-events: write # For uploading results to GitHub Security tab + +jobs: + trivy-scan: + name: Trivy Security Scan + runs-on: ubuntu-latest + + steps: + - name: Checkout code + uses: actions/checkout@v7 + + - name: Run Trivy vulnerability scanner in repo mode + uses: aquasecurity/trivy-action@v0.36.0 + with: + scan-type: "fs" + scan-ref: "." + format: "sarif" + output: "trivy-results.sarif" + severity: "CRITICAL,HIGH" + + - name: Upload Trivy results to GitHub Security tab + uses: github/codeql-action/upload-sarif@v4 + if: always() + with: + sarif_file: "trivy-results.sarif" + + - name: Run Trivy vulnerability scanner (table output) + uses: aquasecurity/trivy-action@v0.36.0 + with: + scan-type: "fs" + scan-ref: "." + format: "table" + severity: "CRITICAL,HIGH" + exit-code: "1"