diff --git a/.github/workflows/go.yml b/.github/workflows/go.yml index 513d4f1..c68a602 100644 --- a/.github/workflows/go.yml +++ b/.github/workflows/go.yml @@ -91,16 +91,3 @@ jobs: uses: codecov/codecov-action@v7 with: flags: ${{ matrix.os }},go-${{ matrix.go }} - - vulnerability-scanning: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v7 - - name: Run Trivy vulnerability scanner in repo mode - uses: aquasecurity/trivy-action@v0.36.0 - with: - scan-type: 'fs' - ignore-unfixed: true - format: 'table' - exit-code: '1' - severity: 'CRITICAL,HIGH,MEDIUM' diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml new file mode 100644 index 0000000..1d73ba8 --- /dev/null +++ b/.github/workflows/security.yml @@ -0,0 +1,32 @@ +name: Trivy Security Scan + +on: + push: + branches: [master] + pull_request: + branches: [master] + schedule: + - cron: "0 0 * * *" # Daily scan at midnight UTC + workflow_dispatch: # Allow manual trigger + +jobs: + trivy-scan: + name: Trivy Security Scan + runs-on: ubuntu-latest + permissions: + contents: read + + steps: + - name: Checkout repository + uses: actions/checkout@v7 + + - name: Run Trivy vulnerability scanner (table output) + uses: aquasecurity/trivy-action@v0.36.0 + if: always() + with: + scan-type: "fs" + scan-ref: "." + format: "table" + severity: "CRITICAL,HIGH" + scanners: "vuln,secret,misconfig" + exit-code: "1" diff --git a/README.md b/README.md index 33aa89c..bf6a201 100644 --- a/README.md +++ b/README.md @@ -3,6 +3,7 @@ [![CodeQL](https://github.com/golang-queue/queue/actions/workflows/codeql.yaml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/codeql.yaml) [![Run Tests](https://github.com/golang-queue/queue/actions/workflows/go.yml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/go.yml) [![codecov](https://codecov.io/gh/golang-queue/queue/branch/master/graph/badge.svg?token=SSo3mHejOE)](https://codecov.io/gh/golang-queue/queue) +[![Trivy Security Scan](https://github.com/golang-queue/queue/actions/workflows/security.yml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/security.yml) [繁體中文](./README.zh-tw.md) | [简体中文](./README.zh-cn.md) diff --git a/README.zh-cn.md b/README.zh-cn.md index 45b5573..998f94e 100644 --- a/README.zh-cn.md +++ b/README.zh-cn.md @@ -3,6 +3,7 @@ [![CodeQL](https://github.com/golang-queue/queue/actions/workflows/codeql.yaml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/codeql.yaml) [![Run Tests](https://github.com/golang-queue/queue/actions/workflows/go.yml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/go.yml) [![codecov](https://codecov.io/gh/golang-queue/queue/branch/master/graph/badge.svg?token=SSo3mHejOE)](https://codecov.io/gh/golang-queue/queue) +[![Trivy Security Scan](https://github.com/golang-queue/queue/actions/workflows/security.yml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/security.yml) [English](./README.md) | [繁體中文](./README.zh-tw.md) diff --git a/README.zh-tw.md b/README.zh-tw.md index 3ba19e3..791d0ca 100644 --- a/README.zh-tw.md +++ b/README.zh-tw.md @@ -3,6 +3,7 @@ [![CodeQL](https://github.com/golang-queue/queue/actions/workflows/codeql.yaml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/codeql.yaml) [![Run Tests](https://github.com/golang-queue/queue/actions/workflows/go.yml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/go.yml) [![codecov](https://codecov.io/gh/golang-queue/queue/branch/master/graph/badge.svg?token=SSo3mHejOE)](https://codecov.io/gh/golang-queue/queue) +[![Trivy Security Scan](https://github.com/golang-queue/queue/actions/workflows/security.yml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/security.yml) [English](./README.md) | [简体中文](./README.zh-cn.md)