name: Trivy Security Scan on: schedule: # Run at 00:00 on day 1 of every 3rd month (January, April, July, October) - cron: "0 0 1 */3 *" workflow_dispatch: # Allow manual trigger push: branches: - master pull_request: branches: - master permissions: contents: read security-events: write # For uploading results to GitHub Security tab jobs: trivy-scan: name: Trivy Security Scan runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@v7 - name: Run Trivy vulnerability scanner in repo mode uses: aquasecurity/trivy-action@v0.36.0 with: scan-type: "fs" scan-ref: "." format: "sarif" output: "trivy-results.sarif" severity: "CRITICAL,HIGH" - name: Upload Trivy results to GitHub Security tab uses: github/codeql-action/upload-sarif@v4 if: always() with: sarif_file: "trivy-results.sarif" - name: Run Trivy vulnerability scanner (table output) uses: aquasecurity/trivy-action@v0.36.0 with: scan-type: "fs" scan-ref: "." format: "table" severity: "CRITICAL,HIGH" exit-code: "1"