Skip to main content
EVOKORE// WORKFLOWS / security-scan.yml
EVOKORE-MCPworkflow · 140 lines

.github/workflows/security-scan.yml

CI / automation

View on GitHub →
name: Security Scan

on:
  push:
    branches: [main]
  pull_request:
    branches: [main]
  schedule:
    - cron: "0 6 * * 1" # Weekly on Monday at 06:00 UTC

jobs:
  trivy-fs:
    name: Dependency CVE Scan
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Get week for cache key
        id: date
        run: echo "week=$(date +%Y-%V)" >> $GITHUB_OUTPUT

      - name: Restore Trivy DB cache
        uses: actions/cache@v4
        with:
          path: ~/.cache/trivy
          key: trivy-db-${{ steps.date.outputs.week }}
          restore-keys: trivy-db-

      - name: Run Trivy filesystem scan
        run: |
          docker run --rm \
            -v "${PWD}:/workspace" \
            -v "${HOME}/.cache/trivy:/root/.cache/trivy" \
            aquasec/trivy:0.68.1 \
            fs \
            --scanners vuln \
            --severity CRITICAL,HIGH \
            --exit-code 1 \
            /workspace

  trivy-config:
    name: IaC Misconfiguration Scan
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Get week for cache key
        id: date
        run: echo "week=$(date +%Y-%V)" >> $GITHUB_OUTPUT

      - name: Restore Trivy DB cache
        uses: actions/cache@v4
        with:
          path: ~/.cache/trivy
          key: trivy-db-${{ steps.date.outputs.week }}
          restore-keys: trivy-db-

      - name: Run Trivy config scan
        run: |
          docker run --rm \
            -v "${PWD}:/workspace" \
            -v "${HOME}/.cache/trivy:/root/.cache/trivy" \
            aquasec/trivy:0.68.1 \
            config \
            --severity CRITICAL,HIGH,MEDIUM \
            --exit-code 0 \
            /workspace

  trivy-secrets:
    name: Secret Leak Detection
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Get week for cache key
        id: date
        run: echo "week=$(date +%Y-%V)" >> $GITHUB_OUTPUT

      - name: Restore Trivy DB cache
        uses: actions/cache@v4
        with:
          path: ~/.cache/trivy
          key: trivy-db-${{ steps.date.outputs.week }}
          restore-keys: trivy-db-

      - name: Run Trivy secret scan
        run: |
          docker run --rm \
            -v "${PWD}:/workspace" \
            -v "${HOME}/.cache/trivy:/root/.cache/trivy" \
            aquasec/trivy:0.68.1 \
            fs \
            --scanners secret \
            --severity CRITICAL,HIGH,MEDIUM \
            --exit-code 1 \
            /workspace

  trivy-sarif:
    name: Trivy SARIF Upload
    runs-on: ubuntu-latest
    permissions:
      security-events: write
    steps:
      - uses: actions/checkout@v4

      - name: Get week for cache key
        id: date
        run: echo "week=$(date +%Y-%V)" >> $GITHUB_OUTPUT

      - name: Restore Trivy DB cache
        uses: actions/cache@v4
        with:
          path: ~/.cache/trivy
          key: trivy-db-${{ steps.date.outputs.week }}
          restore-keys: trivy-db-

      - name: Create results directory
        run: mkdir -p results

      - name: Run Trivy scan (SARIF output)
        run: |
          docker run --rm \
            -v "${PWD}:/workspace" \
            -v "${HOME}/.cache/trivy:/root/.cache/trivy" \
            aquasec/trivy:0.68.1 \
            fs \
            --scanners vuln,secret \
            --severity CRITICAL,HIGH,MEDIUM \
            --exit-code 0 \
            --format sarif \
            --output /workspace/results/trivy-results.sarif \
            /workspace

      - name: Upload Trivy SARIF to GitHub Security
        uses: github/codeql-action/upload-sarif@v4
        if: always()
        with:
          sarif_file: results/trivy-results.sarif
          category: trivy