EVOKORE// WORKFLOWS / security-scan.yml
EVOKORE-MCPworkflow · 140 lines
.github/workflows/security-scan.yml
CI / automation
View on GitHub →name: Security Scan
on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
- cron: "0 6 * * 1" # Weekly on Monday at 06:00 UTC
jobs:
trivy-fs:
name: Dependency CVE Scan
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Get week for cache key
id: date
run: echo "week=$(date +%Y-%V)" >> $GITHUB_OUTPUT
- name: Restore Trivy DB cache
uses: actions/cache@v4
with:
path: ~/.cache/trivy
key: trivy-db-${{ steps.date.outputs.week }}
restore-keys: trivy-db-
- name: Run Trivy filesystem scan
run: |
docker run --rm \
-v "${PWD}:/workspace" \
-v "${HOME}/.cache/trivy:/root/.cache/trivy" \
aquasec/trivy:0.68.1 \
fs \
--scanners vuln \
--severity CRITICAL,HIGH \
--exit-code 1 \
/workspace
trivy-config:
name: IaC Misconfiguration Scan
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Get week for cache key
id: date
run: echo "week=$(date +%Y-%V)" >> $GITHUB_OUTPUT
- name: Restore Trivy DB cache
uses: actions/cache@v4
with:
path: ~/.cache/trivy
key: trivy-db-${{ steps.date.outputs.week }}
restore-keys: trivy-db-
- name: Run Trivy config scan
run: |
docker run --rm \
-v "${PWD}:/workspace" \
-v "${HOME}/.cache/trivy:/root/.cache/trivy" \
aquasec/trivy:0.68.1 \
config \
--severity CRITICAL,HIGH,MEDIUM \
--exit-code 0 \
/workspace
trivy-secrets:
name: Secret Leak Detection
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Get week for cache key
id: date
run: echo "week=$(date +%Y-%V)" >> $GITHUB_OUTPUT
- name: Restore Trivy DB cache
uses: actions/cache@v4
with:
path: ~/.cache/trivy
key: trivy-db-${{ steps.date.outputs.week }}
restore-keys: trivy-db-
- name: Run Trivy secret scan
run: |
docker run --rm \
-v "${PWD}:/workspace" \
-v "${HOME}/.cache/trivy:/root/.cache/trivy" \
aquasec/trivy:0.68.1 \
fs \
--scanners secret \
--severity CRITICAL,HIGH,MEDIUM \
--exit-code 1 \
/workspace
trivy-sarif:
name: Trivy SARIF Upload
runs-on: ubuntu-latest
permissions:
security-events: write
steps:
- uses: actions/checkout@v4
- name: Get week for cache key
id: date
run: echo "week=$(date +%Y-%V)" >> $GITHUB_OUTPUT
- name: Restore Trivy DB cache
uses: actions/cache@v4
with:
path: ~/.cache/trivy
key: trivy-db-${{ steps.date.outputs.week }}
restore-keys: trivy-db-
- name: Create results directory
run: mkdir -p results
- name: Run Trivy scan (SARIF output)
run: |
docker run --rm \
-v "${PWD}:/workspace" \
-v "${HOME}/.cache/trivy:/root/.cache/trivy" \
aquasec/trivy:0.68.1 \
fs \
--scanners vuln,secret \
--severity CRITICAL,HIGH,MEDIUM \
--exit-code 0 \
--format sarif \
--output /workspace/results/trivy-results.sarif \
/workspace
- name: Upload Trivy SARIF to GitHub Security
uses: github/codeql-action/upload-sarif@v4
if: always()
with:
sarif_file: results/trivy-results.sarif
category: trivy