Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
trivy — GitLab CI component for Trivy scanning | Kitploit
Tools/GitLabGitLab/niclas-zone/ci/trivy
Vulnerability ScannersContainer SecurityCloud SecurityDevSecOpsSecret DetectionSupply Chain SecurityMisconfiguration
GitLabniclas-zone/ci/trivy

trivy

GitLab CI component for Trivy scanning

View Repository
152 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Trivy GitLab CI Component

A GitLab CI component for Trivy — the all-in-one security scanner covering container images, filesystems, repositories, Kubernetes clusters, SBOMs, and license compliance. Plug these templates directly into your pipelines to get repeatable scans, GitLab-native reports, and portable artifacts with almost no shell scripting.

Features

  • Full Surface Coverage: Containers, filesystems, root filesystems, Git repositories, VMs, SBOMs, Kubernetes clusters, and more.
  • Multiple Scanners: Vulnerability, misconfiguration/IaC, secret, and license scanning with per-job controls.
  • GitLab Reports: Emits Container Scanning, JUnit, SARIF, and JSON artifacts ready for merge-request insights.
  • Customizable Inputs: Every template exposes knobs for severities, scanners, timeouts, package types, and artifacts.
  • Composable Templates: Mix remote or local scans, SBOM workflows, Rekor attestations, and IaC checks from one component namespace.

Usage

Basic Usage

include:
  - component: $CI_SERVER_FQDN/niclas-zone/ci/trivy/main@latest

stages:
  - test

Remote Image With Custom Severity

include:
  - component: $CI_SERVER_FQDN/niclas-zone/ci/trivy/main@latest
    inputs:
      job_name: "security:remote"
      TRIVY_SCAN_REMOTE_IMAGE: "registry.gitlab.com/group/app:latest"
      severity: "CRITICAL,HIGH,MEDIUM"
      exit_on_vulnerability: true

stages:
  - test

Local Tar / OCI Layout Scan

include:
  - component: $CI_SERVER_FQDN/niclas-zone/ci/trivy/main@latest
    inputs:
      job_name: "security:local"
      TRIVY_SCAN_LOCAL_IMAGES: "dist/"
      TRIVY_SCANNERS: "vuln,secret"
      exit_on_vulnerability: false

stages:
  - test

Component Inputs & Templates

Each template below lists its available inputs and defaults as defined in the component spec, followed by a minimal working example.

Component: templates/main.yml

InputDescriptionDefault
job_nameName of the CI job"trivy scanning"
stagePipeline stage"test"
imageContainer image running Trivy"ghcr.io/aquasecurity/trivy:0.68.1"
TRIVY_NEEDED_STAGEStage that must finish before Trivy runs"build"
TRIVY_SCAN_REMOTE_IMAGERemote image to scan""
TRIVY_SCAN_LOCAL_IMAGESPath to tar/OCI inputs (searches . when empty)""
TRIVY_SCANNERSComma-separated scanners"vuln,secret,misconfig"
severitySeverities to include"CRITICAL,HIGH"
exit_on_vulnerabilityFail job when issues foundtrue
TRIVY_EXTRA_ARGSAdditional CLI flags""
allow_failureAllow job failure without failing pipelinefalse

Example

include:
  - component: $CI_SERVER_FQDN/niclas-zone/ci/trivy/main@latest
    inputs:
      job_name: "trivy:basic"
      TRIVY_SCAN_REMOTE_IMAGE: "nginx:latest"

Component: templates/target_container.yml

InputDescriptionDefault
job_nameCI job name"trivy:scan:containers"
stagePipeline stage"test"
imageTrivy container image"ghcr.io/aquasecurity/trivy:0.68.1"
TRIVY_SCAN_REMOTE_IMAGERemote image reference""
TRIVY_SCAN_LOCAL_IMAGESDirectory/tar for local scans""
TRIVY_SCANNERSEnabled scanners"vuln,secret,misconfig"
TRIVY_IMAGE_SRCImage source backend (remote/docker/...)""
severitySeverities"CRITICAL,HIGH"
exit_on_vulnerabilityFail on severity matchtrue
TRIVY_IGNORE_UNFIXEDIgnore issues without fixestrue
TRIVY_PKG_TYPESPackage types"os,library"
TRIVY_VULN_TYPEDeprecated alias for pkg types""
TRIVY_TIMEOUTCommand timeout"10m"
TRIVY_EXTRA_ARGSExtra CLI args""
TRIVY_DB_REPOSITORYCustom DB mirror""
TRIVY_JAVA_DB_REPOSITORYCustom Java DB mirror""
TRIVY_SKIP_FILESFile glob exclusions""
TRIVY_SKIP_DIRSDirectory exclusions""
allow_failureAllow failure without failing pipelinefalse

Example

include:
  - component: $CI_SERVER_FQDN/niclas-zone/ci/trivy/target_container@latest
    inputs:
      job_name: "trivy:containers"
      TRIVY_SCAN_REMOTE_IMAGE: "registry.gitlab.com/group/service:latest"
      TRIVY_SCANNERS: "vuln,secret"
      exit_on_vulnerability: true

Component: templates/target_filesystem.yml

InputDescriptionDefault
job_nameCI job name"trivy:scan:filesystem"
stagePipeline stage"test"
imageTrivy image"ghcr.io/aquasecurity/trivy:0.68.1"
TRIVY_FS_PATHFile or directory to scan"."
TRIVY_SCANNERSEnabled scanners"vuln,secret"
severitySeverities"CRITICAL,HIGH"
exit_on_vulnerabilityFail on severity matchtrue
TRIVY_IGNORE_UNFIXEDIgnore unfixed issuestrue
TRIVY_PKG_TYPESPackage types"os,library"
TRIVY_TIMEOUTTimeout"10m"
TRIVY_SKIP_FILESFile globs to skip""
TRIVY_SKIP_DIRSDirectories to skip""
TRIVY_EXTRA_ARGSExtra CLI args""
TRIVY_REPORT_BASENAMEArtifact base name"filesystem-scan"
allow_failureAllow job failurefalse

Example

include:
  - component: $CI_SERVER_FQDN/niclas-zone/ci/trivy/target_filesystem@latest
    inputs:
      TRIVY_FS_PATH: "services/api"
      TRIVY_SCANNERS: "vuln,misconfig,secret"

Component: templates/target_rootfs.yml

InputDescriptionDefault
job_nameJob name"trivy:scan:rootfs"
stageStage"test"
imageTrivy image"ghcr.io/aquasecurity/trivy:0.68.1"
TRIVY_ROOTFS_PATHRoot filesystem path"/"
TRIVY_SCANNERSScanners"vuln,secret"
severitySeverities"CRITICAL,HIGH"
exit_on_vulnerabilityFail job on findingstrue
TRIVY_IGNORE_UNFIXEDIgnore unfixedtrue
TRIVY_PKG_TYPESPackage types"os,library"
TRIVY_TIMEOUTTimeout"10m"
TRIVY_SKIP_FILESFiles to skip""
TRIVY_SKIP_DIRSDirectories to skip""
TRIVY_EXTRA_ARGSExtra args""
TRIVY_REPORT_BASENAMEArtifact basename"rootfs-scan"
allow_failureAllow failurefalse

Example

include:
  - component: $CI_SERVER_FQDN/niclas-zone/ci/trivy/target_rootfs@latest
    inputs:
      TRIVY_ROOTFS_PATH: "/mnt/root"
      TRIVY_SCANNERS: "vuln"

Component: templates/target_repository.yml

InputDescriptionDefault
job_nameJob name"trivy:scan:repo"
stageStage"test"
imageTrivy image"ghcr.io/aquasecurity/trivy:0.68.1"
TRIVY_REPO_TARGETLocal path or Git URL"."
TRIVY_REPO_BRANCHRemote branch""
TRIVY_REPO_COMMITCommit hash""
TRIVY_REPO_TAGTag name""
TRIVY_SCANNERSScanners"vuln,secret"
severitySeverities"CRITICAL,HIGH"
exit_on_vulnerabilityFail job on findingstrue
TRIVY_IGNORE_UNFIXEDIgnore unfixedtrue
TRIVY_TIMEOUTTimeout"10m"
TRIVY_SKIP_FILESFiles to skip""
TRIVY_SKIP_DIRSDirs to skip""
TRIVY_EXTRA_ARGSExtra args""
TRIVY_REPORT_BASENAMEArtifact basename"repo-scan"
allow_failureAllow failurefalse

Example

include:
  - component: $CI_SERVER_FQDN/niclas-zone/ci/trivy/target_repository@latest
    inputs:
      TRIVY_REPO_TARGET: "https://github.com/aquasecurity/trivy"
      TRIVY_REPO_BRANCH: "main"

Component: templates/target_vm.yml

Download Tool