From 882a5a84d14c1b8d5f3bc6c05fda2a563c95f624 Mon Sep 17 00:00:00 2001 From: Bo-Yi Wu Date: Wed, 30 Sep 2026 15:05:33 +0800 Subject: [PATCH] ci: add Trivy security scan workflow and badge - add .github/workflows/security.yml mirroring go-signet/signet's Trivy Security Scan (runs on ubuntu-latest; triggers on push, pull request, daily schedule, and workflow_dispatch) so each module has a dedicated trivy scan for vuln/secret/misconfig - remove the vulnerability-scanning job from go.yml to make security.yml the single source of Trivy scans - add a Trivy Security Scan badge to README (and the zh-cn/zh-tw variants for queue) Co-Authored-By: Claude Code --- .github/workflows/go.yml | 13 ------------- .github/workflows/security.yml | 32 ++++++++++++++++++++++++++++++++ README.md | 1 + README.zh-cn.md | 1 + README.zh-tw.md | 1 + 5 files changed, 35 insertions(+), 13 deletions(-) create mode 100644 .github/workflows/security.yml diff --git a/.github/workflows/go.yml b/.github/workflows/go.yml index 513d4f1..c68a602 100644 --- a/.github/workflows/go.yml +++ b/.github/workflows/go.yml @@ -91,16 +91,3 @@ jobs: uses: codecov/codecov-action@v7 with: flags: ${{ matrix.os }},go-${{ matrix.go }} - - vulnerability-scanning: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v7 - - name: Run Trivy vulnerability scanner in repo mode - uses: aquasecurity/trivy-action@v0.36.0 - with: - scan-type: 'fs' - ignore-unfixed: true - format: 'table' - exit-code: '1' - severity: 'CRITICAL,HIGH,MEDIUM' diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml new file mode 100644 index 0000000..1d73ba8 --- /dev/null +++ b/.github/workflows/security.yml @@ -0,0 +1,32 @@ +name: Trivy Security Scan + +on: + push: + branches: [master] + pull_request: + branches: [master] + schedule: + - cron: "0 0 * * *" # Daily scan at midnight UTC + workflow_dispatch: # Allow manual trigger + +jobs: + trivy-scan: + name: Trivy Security Scan + runs-on: ubuntu-latest + permissions: + contents: read + + steps: + - name: Checkout repository + uses: actions/checkout@v7 + + - name: Run Trivy vulnerability scanner (table output) + uses: aquasecurity/trivy-action@v0.36.0 + if: always() + with: + scan-type: "fs" + scan-ref: "." + format: "table" + severity: "CRITICAL,HIGH" + scanners: "vuln,secret,misconfig" + exit-code: "1" diff --git a/README.md b/README.md index 33aa89c..bf6a201 100644 --- a/README.md +++ b/README.md @@ -3,6 +3,7 @@ [![CodeQL](https://github.com/golang-queue/queue/actions/workflows/codeql.yaml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/codeql.yaml) [![Run Tests](https://github.com/golang-queue/queue/actions/workflows/go.yml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/go.yml) [![codecov](https://codecov.io/gh/golang-queue/queue/branch/master/graph/badge.svg?token=SSo3mHejOE)](https://codecov.io/gh/golang-queue/queue) +[![Trivy Security Scan](https://github.com/golang-queue/queue/actions/workflows/security.yml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/security.yml) [繁體中文](./README.zh-tw.md) | [简体中文](./README.zh-cn.md) diff --git a/README.zh-cn.md b/README.zh-cn.md index 45b5573..998f94e 100644 --- a/README.zh-cn.md +++ b/README.zh-cn.md @@ -3,6 +3,7 @@ [![CodeQL](https://github.com/golang-queue/queue/actions/workflows/codeql.yaml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/codeql.yaml) [![Run Tests](https://github.com/golang-queue/queue/actions/workflows/go.yml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/go.yml) [![codecov](https://codecov.io/gh/golang-queue/queue/branch/master/graph/badge.svg?token=SSo3mHejOE)](https://codecov.io/gh/golang-queue/queue) +[![Trivy Security Scan](https://github.com/golang-queue/queue/actions/workflows/security.yml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/security.yml) [English](./README.md) | [繁體中文](./README.zh-tw.md) diff --git a/README.zh-tw.md b/README.zh-tw.md index 3ba19e3..791d0ca 100644 --- a/README.zh-tw.md +++ b/README.zh-tw.md @@ -3,6 +3,7 @@ [![CodeQL](https://github.com/golang-queue/queue/actions/workflows/codeql.yaml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/codeql.yaml) [![Run Tests](https://github.com/golang-queue/queue/actions/workflows/go.yml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/go.yml) [![codecov](https://codecov.io/gh/golang-queue/queue/branch/master/graph/badge.svg?token=SSo3mHejOE)](https://codecov.io/gh/golang-queue/queue) +[![Trivy Security Scan](https://github.com/golang-queue/queue/actions/workflows/security.yml/badge.svg)](https://github.com/golang-queue/queue/actions/workflows/security.yml) [English](./README.md) | [简体中文](./README.zh-cn.md)