[![GitHub Release][release-img]][release] [![GitHub Marketplace][marketplace-img]][marketplace] [![License][license-img]][license]

name: build on: push: branches: - main pull_request: jobs: build: name: Build runs-on: ubuntu-24.04 steps: - name: Checkout code uses: actions/checkout@v4 - name: Build an image from Dockerfile run: docker build -t docker.io/my-organization/my-app:${{ github.sha }} . - name: Run Trivy vulnerability scanner uses: aquasecurity/[email protected] with: image-ref: 'docker.io/my-organization/my-app:${{ github.sha }}' format: 'table' exit-code: '1' ignore-unfixed: true vuln-type: 'os,library' severity: 'CRITICAL,HIGH'
### 扫描CI流水线(使用Trivy配置)```yaml
name: build
on:
push:
branches:
- main
pull_request:
jobs:
build:
name: Build
runs-on: ubuntu-24.04
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Run Trivy vulnerability scanner in fs mode
uses: aquasecurity/[email protected]
with:
scan-type: 'fs'
scan-ref: '.'
trivy-config: trivy.yaml
在这种情况下,trivy.yaml 是一个作为仓库一部分检入的YAML配置文件。详细信息可在Trivy网站上查阅,以下是一个示例:```yaml
format: json
exit-code: 1
severity: CRITICAL
secret:
config: config/trivy/secret.yaml
可以在`trivy.yaml`文件中定义所有选项。通过操作指定单个选项是为了向后兼容。以下选项无法通过配置文件定义,必须明确指定:
- `scan-ref`:如果使用`fs`、`repo`扫描。
- `image-ref`:如果使用`image`扫描。
- `scan-type`:用于定义扫描类型,例如`image`、`fs`、`repo`等。
#### 选项优先顺序
Trivy使用[Viper](https://github.com/spf13/viper),它对选项有明确的优先顺序。顺序如下:
- GitHub Action标志
- 环境变量
- 配置文件
- 默认值
### 缓存
该操作内置了缓存和恢复[漏洞数据库](https://github.com/aquasecurity/trivy-db)、[Java数据库](https://github.com/aquasecurity/trivy-java-db)和[检查包](https://github.com/aquasecurity/trivy-checks)的功能(如果在扫描过程中下载了它们)。
缓存默认存储在`$GITHUB_WORKSPACE/.cache/trivy`目录中。
缓存会在扫描开始前恢复,并在扫描完成后保存。
它在底层使用[actions/cache](https://github.com/actions/cache),但所需配置更少。
缓存输入是可选的,默认开启缓存。
#### 禁用缓存
如果要禁用缓存,请将`cache`输入设置为`false`,但我们建议保持启用状态,以避免速率限制问题。```yaml
- name: Run Trivy scanner without cache
uses: aquasecurity/[email protected]
with:
scan-type: 'fs'
scan-ref: '.'
cache: 'false'
请注意,GitHub Actions 中分支之间的缓存访问存在限制。
默认情况下,工作流只能访问和恢复在当前分支或默认分支(通常是 main 或 master)中创建的缓存。
如果需要在分支之间共享缓存,可能需要先在默认分支中创建缓存,再在当前分支中恢复它。
为了优化工作流,你可以设置一个定时任务(cron job)定期更新默认分支中的缓存。 这样后续扫描就可以直接使用缓存的数据库,而无需重复下载。```yaml
name: Update Trivy Cache
on: schedule: - cron: '0 0 * * *' # Run daily at midnight UTC workflow_dispatch: # Allow manual triggering
jobs: update-trivy-db: runs-on: ubuntu-latest steps: - name: Setup oras uses: oras-project/setup-oras@v1
- name: Get current date
id: date
run: echo "date=$(date +'%Y-%m-%d')" >> $GITHUB_OUTPUT
- name: Download and extract the vulnerability DB
run: |
mkdir -p $GITHUB_WORKSPACE/.cache/trivy/db
oras pull ghcr.io/aquasecurity/trivy-db:2
tar -xzf db.tar.gz -C $GITHUB_WORKSPACE/.cache/trivy/db
rm db.tar.gz
- name: Download and extract the Java DB
run: |
mkdir -p $GITHUB_WORKSPACE/.cache/trivy/java-db
oras pull ghcr.io/aquasecurity/trivy-java-db:1
tar -xzf javadb.tar.gz -C $GITHUB_WORKSPACE/.cache/trivy/java-db
rm javadb.tar.gz
- name: Cache DBs
uses: actions/cache/save@v4
with:
path: ${{ github.workspace }}/.cache/trivy
key: cache-trivy-${{ steps.date.outputs.date }}
当运行扫描时,设置环境变量 `TRIVY_SKIP_DB_UPDATE` 和 `TRIVY_SKIP_JAVA_DB_UPDATE` 以跳过下载过程。```yaml
- name: Run Trivy scanner without downloading DBs
uses: aquasecurity/[email protected]
with:
scan-type: 'image'
scan-ref: 'myimage'
env:
TRIVY_SKIP_DB_UPDATE: true
TRIVY_SKIP_JAVA_DB_UPDATE: true
默认情况下,该操作会调用 aquasecurity/setup-trivy 作为第一步,安装由 version 输入指定的 trivy 版本。如果您已通过其他方式安装了 trivy,例如直接调用 aquasecurity/setup-trivy,或者多次调用此操作,则可以使用 skip-setup-trivy 输入来禁用此步骤。
name: build on: push: branches: - main pull_request: jobs: build: name: Build runs-on: ubuntu-24.04 steps: - name: Checkout code uses: actions/checkout@v4
- name: Manual Trivy Setup
uses: aquasecurity/[email protected]
with:
cache: true
version: v0.72.0
- name: Run Trivy vulnerability scanner in repo mode
uses: aquasecurity/[email protected]
with:
scan-type: 'fs'
ignore-unfixed: true
format: 'sarif'
output: 'trivy-results.sarif'
severity: 'CRITICAL'
skip-setup-trivy: true
#### 多次调用Trivy Action时跳过设置
另一个常见用例是当构建多次调用此操作时,在这种情况下,我们可以在后续调用中将 `skip-setup-trivy` 设置为 `true`,例如```yaml
name: build
on:
push:
branches:
- main
pull_request:
jobs:
test:
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- name: Check out Git repository
uses: actions/checkout@v4
# The first call to the action will invoke setup-trivy and install trivy
- name: Generate Trivy Vulnerability Report
uses: aquasecurity/[email protected]
with:
scan-type: "fs"
output: trivy-report.json
format: json
scan-ref: .
exit-code: 0
- name: Upload Vulnerability Scan Results
uses: actions/upload-artifact@v4
with:
name: trivy-report
path: trivy-report.json
retention-days: 30
- name: Fail build on High/Criticial Vulnerabilities
uses: aquasecurity/[email protected]
with:
scan-type: "fs"
format: table
scan-ref: .
severity: HIGH,CRITICAL
ignore-unfixed: true
exit-code: 1
# On a subsequent call to the action we know trivy is already installed so can skip this
skip-setup-trivy: true
GitHub Enterprise Server (GHES) 会使用一个无效的 github.token 来访问 https://github.com 服务器。
因此,您无法通过 setup-trivy 操作来安装 Trivy。