sandbox-coprs/Trivy Scan

Scan vulns with Trivy

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
outputwrites results to a file with the specified file name (without extension)novulnerabilites
artifactName of the artifact to uploadyesvulnerabilites
upload-sarifTo upload the sarif report in GitHubno""
formatoutput format (table, json, template)nosarif,json,template
templateuse an existing template for rendering output (@/contrib/sarif.tpl, @/contrib/gitlab.tpl, @/contrib/junit.tplno@/contrib/html.tpl
image-refimage reference (for backward compatibility)yes
scan-typeScan type to use for scanning vulnerabilitynoimage
inputreference of tar file to scanno""
scan-refScan referenceno.
exit-codeexit code when vulnerabilities were foundno0
ignore-unfixedignore unfixed vulnerabilitiesnofalse
vuln-typecomma-separated list of vulnerability types (os,library)noos,library
severityseverities of vulnerabilities to be displayednoUNKNOWN,LOW,MEDIUM,HIGH,CRITICAL
skip-dirscomma separated list of directories where traversal is skippedno""
skip-filescomma separated list of files to be skippedno""
cache-dirspecify where the cache is storedno""
timeouttimeout (default 5m0s)no""
ignore-policyfilter vulnerabilities with OPA rego languageno""
hide-progresshide progress outputnotrue
list-all-pkgsoutput all packages regardless of vulnerabilitynofalse
security-checkscomma-separated list of what security issues to detectno""
trivyignorescomma-separated list of relative paths in repository to one or more .trivyignore filesno""

no outputs