aquasecurity/trivy-action:README に基づく導入ガイド
README、メタデータ、ライセンスに基づく aquasecurity/trivy-action の導入と確認ガイドです。
プロジェクトの範囲
aquasecurity/trivy-action の README はプロジェクトを「Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities」と説明しています。ここではリポジトリで確認できる事実だけを整理します。star 数やバッジは注目度の手掛かりであり、品質の証明ではありません。「Scan CI Pipeline (w/ Trivy Config)」には次の説明があります。In this case trivy.yaml is a YAML configuration that is checked in as part of the repo. Detailed information is available on the Trivy website but an example is as follows:。これは範囲の説明であり、本番検証の結果ではありません。
向いている用途
README の「Scan CI Pipeline (w/ Trivy Config)」にある内容から、用途が合うかを先に判断できます。scan-type: To define the scan type, e.g. image, fs, repo, etc.。目的が違うなら、人気だけで採用する理由にはなりません。プロジェクト名やコマンドは原文のまま残し、一次資料へ戻って用語を確認できるようにしています。 README には次の確認可能な項目もあります。Using Trivy if you don't have code scanning enabled。初回テストの材料にはなりますが、実際の環境での確認を省略する理由にはなりません。
動作の考え方
動作の説明は「Order of preference for options」など複数の箇所に分かれています。確認できる情報は次の通りです。Trivy uses Viper which has a defined precedence order for options. The order is as follows:。書かれていない構成、性能、セキュリティを推測で補いません。導入時はディレクトリ、設定ファイル、release 履歴を確認してください。
インストールと初回起動
初回導入は README の入口から始めます。確認できるコマンドは次の通りです。 name: build on: push: branches: - main pull_request: jobs: build: name: Build runs-on: ubuntu-24.04 steps: - name: Checkout code uses: actions/checkout@v4 - name: Build an image from Dockerfile run: docker build -t docker.io/my-organization/my-app:${{ github.sha }} . - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@v0.36.0 with: image-ref: 'docker.io/my-organization/my-app:${{ github.sh 実行可能なコマンドがない場合は手順を作らず、「Table of Contents」で依存関係、待受ポート、初回設定を確認します。
設定と日常運用
日常運用は公式文書の範囲に限ります。「Cache」にはThe action has a built-in functionality for caching and restoring the vulnerability DB if they are downloaded during the scan. The cache is stored in the $GITHUBWORKSPACE/.cache/trivy directory by default.とあります。設定、環境変数、権限、データ保存先は明記されたものだけを扱います。未記載の既定値は隔離環境で確認し、戻せる設定を保存してください。 同じ資料にはUsing Trivy if you don't have code scanning enabledともあります。