xpeditis2.0/.gitea/actions/setup-trivy/action.yml
2026-09-23 08:57:58 +02:00

17 lines
773 B
YAML

name: Install verified Trivy
description: Install a pinned scanner with a checked SHA256, without elevated privileges.
runs:
using: composite
steps:
- shell: bash
run: |
set -euo pipefail
install_dir="$RUNNER_TEMP/trivy-bin"
mkdir -p "$install_dir"
curl --fail --silent --show-error --location --retry 3 --max-time 120 \
https://github.com/aquasecurity/trivy/releases/download/v0.74.0/trivy_0.74.0_Linux-64bit.tar.gz \
--output "$install_dir/trivy.tar.gz"
echo "2ae6fe3ee734b7fdf11335663e18c75ea12dccc76062f09f164a3b0f8be4371a $install_dir/trivy.tar.gz" | sha256sum --check --strict
tar -xzf "$install_dir/trivy.tar.gz" -C "$install_dir" trivy
echo "$install_dir" >> "$GITHUB_PATH"