ci: add Trivy security scan workflow and badge - #175
Merged
Merged
Conversation
- add .github/workflows/security.yml mirroring go-signet/signet's Trivy Security Scan (runs on ubuntu-latest; triggers on push, pull request, daily schedule, and workflow_dispatch) so each module has a dedicated trivy scan for vuln/secret/misconfig - remove the vulnerability-scanning job from go.yml to make security.yml the single source of Trivy scans - add a Trivy Security Scan badge to README (and the zh-cn/zh-tw variants for queue) Co-Authored-By: Claude Code <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add a dedicated Trivy security scan GitHub Actions workflow to this repo (mirroring go-signet/signet) and surface it with a README badge.
.github/workflows/security.yml—Trivy Security Scanjob (table output;vuln,secret,misconfigscanners;CRITICAL,HIGHseverity;exit-code: 1) triggered onpush,pull_request, a dailyschedule(0 0 * * *), andworkflow_dispatch. Runner isubuntu-latest(signet usesself-hosted; this public repo runs on GitHub-hosted runners).vulnerability-scanningjob fromgo.ymlsosecurity.ymlis the single source of Trivy scans (avoids running trivy twice on every push/PR).Trivy Security Scanbadge toREADME.md(and toqueue'sREADME.zh-cn.md/README.zh-tw.mdtranslated variants for consistency).Related issues
Architecture / flow
AI authorship
.github/workflows/security.yml,.github/workflows/go.yml(trivy job removed),README.md(+ zh-cn/zh-tw for queue)Change classification
CI / security-pipeline changes affect every contributor's workflow.
Plan reference
Mirror
go-signet/signetsecurity.ymlacross allgolang-queue/*modules and expose a Trivy badge in every README.Verification
Setup
ci/trivy-security-scan.aquasecurity/trivy-action@v0.36.0).Automated checks
gh workflow listTrivy Security Scanalongside existing workflowsgrep vulnerability-scanning .github/workflows/go.ymlgrep 'Trivy Security Scan' README.mdworkflow_dispatchofTrivy Security Scan.and exits 0 when no CRITICAL/HIGH vuln/secret/misconfigBehavioral scenarios
Scenario: Trivy scan runs on push and on schedule
Trivy Security Scanworkflow; it scans the repo tree for vulnerability / secret / misconfig issues and fails (exit 1) on CRITICAL/HIGH.Trivy Security Scanworkflow run startsworkflow_dispatchmanuallySecurity check
permissions: contents: readRisk and rollback
vulnerability-scanningjob fromgo.ymlmoves Trivy intosecurity.yml; if the badge/workfile has a typo, the daily scan would not run. The first pushed run validates this.vulnerability-scanningjob ingo.ymland removesecurity.yml).Reviewer guide
.github/workflows/security.ymltriggers (push/PR against the default branch —masterforqueue,mainelsewhere; daily schedule) andgo.yml(trivy job removed cleanly with no orphaned keys).https://github.com/<org>/<repo>/actions/workflows/security.yml.🤖 Generated with Claude Code