skpr/Trivy scan image and upload SARIF
Pull an image, run Trivy SARIF scan, and upload results to GitHub Code Scanning.
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Stale
- License
- None
Inputs
| name | description | required | default |
|---|---|---|---|
| image-ref | Full image reference, e.g. ghcr.io/org/image:tag | yes | — |
| severity | — | no | HIGH,CRITICAL |
| ignore-unfixed | — | no | true |
| vuln-type | — | no | os,library |
| sarif-file | — | no | trivy-results.sarif |
Outputs
no outputs