From 29696a7deaf4c907bea6cbae644e8dc6a0041ae9 Mon Sep 17 00:00:00 2001 From: Daniel Pacak Date: Tue, 2 Jun 2020 17:07:34 +0200 Subject: [PATCH] chore: Init project Signed-off-by: Daniel Pacak --- Dockerfile | 1 + README.md | 2 ++ action.yaml | 13 +++++++++++++ 3 files changed, 16 insertions(+) create mode 100644 Dockerfile create mode 100644 README.md create mode 100644 action.yaml diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..5275183 --- /dev/null +++ b/Dockerfile @@ -0,0 +1 @@ +FROM aquasec.trivy:latest diff --git a/README.md b/README.md new file mode 100644 index 0000000..94bc53c --- /dev/null +++ b/README.md @@ -0,0 +1,2 @@ +# Trivy GitHub Action + diff --git a/action.yaml b/action.yaml new file mode 100644 index 0000000..1128f1c --- /dev/null +++ b/action.yaml @@ -0,0 +1,13 @@ +name: 'Trivy Action' +description: 'Scan container image for vulnerabilities with Trivy' +inputs: + image-ref: # Docker image reference, e.g. alpine:3.10.2 + description: 'Docker image reference' +outputs: + scan-report: + description: 'Vulnerability report is JSON' +runs: + using: 'docker' + image: 'Dockerfile' + args: + - ${{ inputs.image-ref }}