StepSecurity Logo
StepSecurity
LoginStart free
step-security/trivy-action

step-security/trivy-action

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities.

GitHubGitHub Repository

0 stars

Score updated 17 days ago

GitHub Actions security score

step-security/trivy-action

Score

6/10

License

No License

Maintained

Maintained by StepSecurity

Vulnerabilities

0 existing vulnerabilities detected

Branch protection

branch protection is not maximal on development and all release branches

Manual code review

Upstream changes are reviewed before merging

Secure publishing

Reproducible builds with SBOM and provenance

Signed commits

All commits are signed

Automated security tools

Findings from tools are triaged and fixed before each change

Popular

Used by StepSecurity enterprise customers

Security Policy

security policy file not detected