adfinis/Container Scanning Action

Action for scanning containers with trivy. Supports cosign (attestations and signing.)

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit May 22, 2026
License
LGPL

Pinned Snippet

workflow.ymlSHA-pinned
uses: adfinis/container-scanning-action@3b2ed30535dfc19639b38a4712df6fb5b739baa4 # v0.4.4

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
image-refImage to scanyes
attestCreate an attestation using cosignnofalse
digestThe images digestno
registryThe container registrynoghcr.io
tokenGithub Tokenyes

no outputs