diff --git a/.github/workflows/trivy.yml b/.github/workflows/trivy.yml new file mode 100644 index 0000000000..1a22886a2d --- /dev/null +++ b/.github/workflows/trivy.yml @@ -0,0 +1,20 @@ +name: CI + +on: + push: + branches: ["*"] + pull_request: + branches: [main] + +jobs: + build: + name: Trivy Scan + runs-on: ubuntu-latest + steps: + - name: Install Trivy + run: | + wget https://github.com/aquasecurity/trivy/releases/download/v0.38.0/trivy_0.38.0_Linux-64bit.deb + sudo dpkg -i trivy_0.18.3_Linux-64bit.deb + - name: Scan Image + run: | + trivy image --timeout 60m ghcr.io/containerd/nydus-snapshotter:latest