Trivy Security Scan #131
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Trivy Security Scan | |
| on: | |
| pull_request: | |
| push: | |
| schedule: | |
| - cron: "0 2 * * 1" | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| security-events: write | |
| jobs: | |
| lockfile-drift: | |
| name: Lockfile Drift Check | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: Set up Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: 20 | |
| cache: npm | |
| cache-dependency-path: frontend/package-lock.json | |
| - name: Check Node.js lockfile drift | |
| run: | | |
| echo "Checking frontend package-lock.json drift..." | |
| cd frontend | |
| npm ci --dry-run | |
| - name: Set up Rust | |
| uses: dtolnay/rust-toolchain@stable | |
| - name: Check Rust lockfile drift | |
| run: | | |
| echo "Checking Rust Cargo.lock drift..." | |
| cd smartcontract | |
| cargo metadata --locked | |
| trivy-filesystem: | |
| name: Trivy Filesystem Scan | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: Run Trivy filesystem scan | |
| uses: aquasecurity/trivy-action@0.24.0 | |
| with: | |
| scan-type: fs | |
| scan-ref: . | |
| scanners: vuln,misconfig,secret | |
| severity: HIGH,CRITICAL | |
| ignore-unfixed: true | |
| format: sarif | |
| output: trivy-fs-results.sarif | |
| exit-code: "1" | |
| - name: Upload filesystem scan results | |
| if: always() | |
| uses: github/codeql-action/upload-sarif@v3 | |
| with: | |
| sarif_file: trivy-fs-results.sarif | |
| category: trivy-filesystem | |
| trivy-docker: | |
| name: Trivy Docker Image Scan | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - name: backend | |
| context: ./backend | |
| dockerfile: ./backend/Dockerfile | |
| image: stellarinsure-backend:trivy | |
| - name: frontend | |
| context: ./frontend | |
| dockerfile: ./frontend/Dockerfile | |
| image: stellarinsure-frontend:trivy | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: Build ${{ matrix.name }} Docker image | |
| run: | | |
| docker build \ | |
| --file "${{ matrix.dockerfile }}" \ | |
| --tag "${{ matrix.image }}" \ | |
| "${{ matrix.context }}" | |
| - name: Run Trivy Docker image scan for ${{ matrix.name }} | |
| uses: aquasecurity/trivy-action@0.24.0 | |
| with: | |
| image-ref: ${{ matrix.image }} | |
| scanners: vuln | |
| severity: HIGH,CRITICAL | |
| ignore-unfixed: true | |
| format: sarif | |
| output: trivy-image-${{ matrix.name }}-results.sarif | |
| exit-code: "1" | |
| - name: Upload Docker scan results for ${{ matrix.name }} | |
| if: always() | |
| uses: github/codeql-action/upload-sarif@v3 | |
| with: | |
| sarif_file: trivy-image-${{ matrix.name }}-results.sarif | |
| category: trivy-docker-${{ matrix.name }} |