cloudbees-io/trivy-hybrid

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jul 10, 2026
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: cloudbees-io/trivy-plugin@6723a951a3928a28cef553648ddaba7456a9bdc6 # v1

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
binary-tar-pathPath to the binary to scanyes
licenseFlag to enable license scanning (true/false)no""
namedescription
critical-countA string containing the number of Critical security findings discovered during the scan.
very-high-countA string containing the number of Very High security findings discovered during the scan.
high-countA string containing the number of High security findings discovered during the scan.
medium-countA string containing the number of Medium security findings discovered during the scan.
low-countA string containing the number of Low security findings discovered during the scan.
policy-subjectA json value containing the details about the vulnerability scan summary & details.