Skip to content

Run Trivy scan to api #872

Run Trivy scan to api

Run Trivy scan to api #872

Workflow file for this run

name: Run Trivy scan to api
on:
pull_request:
branches:
- main
paths:
- api/**
push:
branches:
- main
paths:
- api/**
schedule:
- cron: "30 19 * * *"
# Allows you to run this workflow manually from the Actions tab
workflow_dispatch:
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Run Trivy vulnerability scanner in fs mode
uses: aquasecurity/trivy-action@master
with:
scan-type: "fs"
scan-ref: "./api"
trivy-config: trivy.yaml
env:
TRIVY_DB_REPOSITORY: ghcr.io/aquasecurity/trivy-db,public.ecr.aws/aquasecurity/trivy-db
TRIVY_JAVA_DB_REPOSITORY: ghcr.io/aquasecurity/trivy-java-db,public.ecr.aws/aquasecurity/trivy-java-db