Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
trivy-action — 作为GitHub Action运行Trivy,扫描您的Docker容器镜像中的漏洞 | Kitploit
工具/GitHubGitHub/aquasecurity/trivy-action
漏洞扫描器容器安全代码分析云安全DevSecOps秘密检测供应链安全错误配置
GitHubaquasecurity/trivy-action

trivy-action

作为GitHub Action运行Trivy,扫描您的Docker容器镜像中的漏洞

查看仓库
1.4k357271个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Trivy Action

Trivy 的 GitHub Action

[![GitHub Release][release-img]][release] [![GitHub Marketplace][marketplace-img]][marketplace] [![License][license-img]][license]

目录

  • 用法
    • 扫描 CI 流水线
    • 扫描 CI 流水线(使用 Trivy 配置)
    • 缓存
    • Trivy 设置
    • 扫描 Tarball 文件
    • 使用 Trivy 与模板
    • 使用 Trivy 与 GitHub 代码扫描
    • 使用 Trivy 扫描 Git 仓库
    • 使用 Trivy 扫描根文件系统目录
    • 使用 Trivy 扫描基础设施即代码
    • 使用 Trivy 生成 SBOM
    • 使用 Trivy 扫描私有注册表
    • 如果未启用代码扫描,请使用 Trivy
  • 自定义
    • 输入
    • 环境变量
    • Trivy 配置文件

用法

扫描 CI 流水线```yaml

name: build on: push: branches: - main pull_request: jobs: build: name: Build runs-on: ubuntu-24.04 steps: - name: Checkout code uses: actions/checkout@v4 - name: Build an image from Dockerfile run: docker build -t docker.io/my-organization/my-app:${{ github.sha }} . - name: Run Trivy vulnerability scanner uses: aquasecurity/[email protected] with: image-ref: 'docker.io/my-organization/my-app:${{ github.sha }}' format: 'table' exit-code: '1' ignore-unfixed: true vuln-type: 'os,library' severity: 'CRITICAL,HIGH'

### 扫描CI流水线(使用Trivy配置)```yaml
name: build
on:
  push:
    branches:
    - main
  pull_request:
jobs:
  build:
    name: Build
    runs-on: ubuntu-24.04
    steps:
    - name: Checkout code
      uses: actions/checkout@v4

    - name: Run Trivy vulnerability scanner in fs mode
      uses: aquasecurity/[email protected]
      with:
        scan-type: 'fs'
        scan-ref: '.'
        trivy-config: trivy.yaml

在这种情况下,trivy.yaml 是一个作为仓库一部分检入的YAML配置文件。详细信息可在Trivy网站上查阅,以下是一个示例:```yaml format: json exit-code: 1 severity: CRITICAL secret: config: config/trivy/secret.yaml

可以在`trivy.yaml`文件中定义所有选项。通过操作指定单个选项是为了向后兼容。以下选项无法通过配置文件定义,必须明确指定:
- `scan-ref`:如果使用`fs`、`repo`扫描。
- `image-ref`:如果使用`image`扫描。
- `scan-type`:用于定义扫描类型,例如`image`、`fs`、`repo`等。

#### 选项优先顺序
Trivy使用[Viper](https://github.com/spf13/viper),它对选项有明确的优先顺序。顺序如下:
- GitHub Action标志
- 环境变量
- 配置文件
- 默认值

### 缓存
该操作内置了缓存和恢复[漏洞数据库](https://github.com/aquasecurity/trivy-db)、[Java数据库](https://github.com/aquasecurity/trivy-java-db)和[检查包](https://github.com/aquasecurity/trivy-checks)的功能(如果在扫描过程中下载了它们)。
缓存默认存储在`$GITHUB_WORKSPACE/.cache/trivy`目录中。
缓存会在扫描开始前恢复,并在扫描完成后保存。

它在底层使用[actions/cache](https://github.com/actions/cache),但所需配置更少。
缓存输入是可选的,默认开启缓存。

#### 禁用缓存
如果要禁用缓存,请将`cache`输入设置为`false`,但我们建议保持启用状态,以避免速率限制问题。```yaml
    - name: Run Trivy scanner without cache
      uses: aquasecurity/[email protected]
      with:
        scan-type: 'fs'
        scan-ref: '.'
        cache: 'false'

在默认分支中更新缓存

请注意,GitHub Actions 中分支之间的缓存访问存在限制。 默认情况下,工作流只能访问和恢复在当前分支或默认分支(通常是 main 或 master)中创建的缓存。 如果需要在分支之间共享缓存,可能需要先在默认分支中创建缓存,再在当前分支中恢复它。

为了优化工作流,你可以设置一个定时任务(cron job)定期更新默认分支中的缓存。 这样后续扫描就可以直接使用缓存的数据库,而无需重复下载。```yaml

Note: This workflow only updates the cache. You should create a separate workflow for your actual Trivy scans.

In your scan workflow, set TRIVY_SKIP_DB_UPDATE=true and TRIVY_SKIP_JAVA_DB_UPDATE=true.

name: Update Trivy Cache

on: schedule: - cron: '0 0 * * *' # Run daily at midnight UTC workflow_dispatch: # Allow manual triggering

jobs: update-trivy-db: runs-on: ubuntu-latest steps: - name: Setup oras uses: oras-project/setup-oras@v1

  - name: Get current date
    id: date
    run: echo "date=$(date +'%Y-%m-%d')" >> $GITHUB_OUTPUT

  - name: Download and extract the vulnerability DB
    run: |
      mkdir -p $GITHUB_WORKSPACE/.cache/trivy/db
      oras pull ghcr.io/aquasecurity/trivy-db:2
      tar -xzf db.tar.gz -C $GITHUB_WORKSPACE/.cache/trivy/db
      rm db.tar.gz

  - name: Download and extract the Java DB
    run: |
      mkdir -p $GITHUB_WORKSPACE/.cache/trivy/java-db
      oras pull ghcr.io/aquasecurity/trivy-java-db:1
      tar -xzf javadb.tar.gz -C $GITHUB_WORKSPACE/.cache/trivy/java-db
      rm javadb.tar.gz

  - name: Cache DBs
    uses: actions/cache/save@v4
    with:
      path: ${{ github.workspace }}/.cache/trivy
      key: cache-trivy-${{ steps.date.outputs.date }}
当运行扫描时,设置环境变量 `TRIVY_SKIP_DB_UPDATE` 和 `TRIVY_SKIP_JAVA_DB_UPDATE` 以跳过下载过程。```yaml
    - name: Run Trivy scanner without downloading DBs
      uses: aquasecurity/[email protected]
      with:
        scan-type: 'image'
        scan-ref: 'myimage'
      env:
        TRIVY_SKIP_DB_UPDATE: true
        TRIVY_SKIP_JAVA_DB_UPDATE: true

Trivy 设置

默认情况下,该操作会调用 aquasecurity/setup-trivy 作为第一步,安装由 version 输入指定的 trivy 版本。如果您已通过其他方式安装了 trivy,例如直接调用 aquasecurity/setup-trivy,或者多次调用此操作,则可以使用 skip-setup-trivy 输入来禁用此步骤。

手动设置 Trivy```yaml

name: build on: push: branches: - main pull_request: jobs: build: name: Build runs-on: ubuntu-24.04 steps: - name: Checkout code uses: actions/checkout@v4

- name: Manual Trivy Setup
  uses: aquasecurity/[email protected]
  with:
    cache: true
    version: v0.72.0

- name: Run Trivy vulnerability scanner in repo mode
  uses: aquasecurity/[email protected]
  with:
    scan-type: 'fs'
    ignore-unfixed: true
    format: 'sarif'
    output: 'trivy-results.sarif'
    severity: 'CRITICAL'
    skip-setup-trivy: true
#### 多次调用Trivy Action时跳过设置
另一个常见用例是当构建多次调用此操作时,在这种情况下,我们可以在后续调用中将 `skip-setup-trivy` 设置为 `true`,例如```yaml
name: build

on:
  push:
    branches:
      - main
  pull_request:

jobs:
  test:
    runs-on: ubuntu-latest
    permissions:
      contents: read
    steps:
      - name: Check out Git repository
        uses: actions/checkout@v4

      # The first call to the action will invoke setup-trivy and install trivy
      - name: Generate Trivy Vulnerability Report
        uses: aquasecurity/[email protected]
        with:
          scan-type: "fs"
          output: trivy-report.json
          format: json
          scan-ref: .
          exit-code: 0

      - name: Upload Vulnerability Scan Results
        uses: actions/upload-artifact@v4
        with:
          name: trivy-report
          path: trivy-report.json
          retention-days: 30

      - name: Fail build on High/Criticial Vulnerabilities
        uses: aquasecurity/[email protected]
        with:
          scan-type: "fs"
          format: table
          scan-ref: .
          severity: HIGH,CRITICAL
          ignore-unfixed: true
          exit-code: 1
          # On a subsequent call to the action we know trivy is already installed so can skip this
          skip-setup-trivy: true

使用非默认令牌安装 Trivy

GitHub Enterprise Server (GHES) 会使用一个无效的 github.token 来访问 https://github.com 服务器。 因此,您无法通过 setup-trivy 操作来安装 Trivy。

下载工具