aquasecurity/trivy-action:README 來源編輯指南
根據 README、倉庫資料與授權整理 aquasecurity/trivy-action 的安裝與核驗路徑。
專案定位
aquasecurity/trivy-action 的 README 將專案描述為「Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities」。本文只整理倉庫可直接核對的內容,不把 star、Fork 或宣傳語當成品質證明。README 在「Scan CI Pipeline (w/ Trivy Config)」下寫到:In this case trivy.yaml is a YAML configuration that is checked in as part of the repo. Detailed information is available on the Trivy website but an example is as follows:。這說明的是專案邊界,不是已完成的生產驗證。
適用場景
從 README 的「Scan CI Pipeline (w/ Trivy Config)」與相關條目,可以先判斷它是否處理你的實際問題:scan-type: To define the scan type, e.g. image, fs, repo, etc.。若需求不同,不應只因專案熱度就採用。本文保留原始專案名、命令與元件名,方便回到一手來源核對。 README 另外列出一項可核對的資訊:Using Trivy if you don't have code scanning enabled。這類原文條目可用來設計試跑步驟,但不能取代實際環境測試。
運作方式
README 將運作方式分散在「Order of preference for options」等段落。可確認的線索包括:Trivy uses Viper which has a defined precedence order for options. The order is as follows:。本文不把未寫出的架構、效能或安全邊界補成結論;真正的執行鏈仍要配合目錄、設定檔與版本標籤檢查。
安裝與第一次執行
第一次安裝應從 README 指出的入口開始。目前可核對的命令是: name: build on: push: branches: - main pull_request: jobs: build: name: Build runs-on: ubuntu-24.04 steps: - name: Checkout code uses: actions/checkout@v4 - name: Build an image from Dockerfile run: docker build -t docker.io/my-organization/my-app:${{ github.sha }} . - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@v0.36.0 with: image-ref: 'docker.io/my-organization/my-app:${{ github.sh 如果倉庫沒有命令,本文不會自行編造步驟,而是建議先閱讀「Table of Contents」,確認系統依賴、預設埠與首次初始化。
設定與日常使用
日常使用取決於專案文件。README 的「Cache」段落提到:The action has a built-in functionality for caching and restoring the vulnerability DB if they are downloaded during the scan. The cache is stored in the $GITHUBWORKSPACE/.cache/trivy directory by default.。設定檔、環境變數、權限與資料目錄只在來源明確時才會記錄;沒有寫出的預設值,應在測試環境驗證並保留回滾副本。 同一部分也提到:Using Trivy if you don't have code scanning enabled。