Skip to content

Testing out the Trivy setup of AppSec - #299

Closed
ajaust wants to merge 2 commits into
equinor:mainfrom
ajaust:maint/update-container-scanning-appsec
Closed

Testing out the Trivy setup of AppSec#299
ajaust wants to merge 2 commits into
equinor:mainfrom
ajaust:maint/update-container-scanning-appsec

Conversation

@ajaust

@ajaust ajaust commented Nov 4, 2025

Copy link
Copy Markdown
Contributor

No description provided.

Trivy [1] is the currently recommended tool for container scanning since
Snyk is being phased out. We pin the version of the Trivy Action [2] to
its most recent release as recommended for third party Actions [3]. This
is recommended to safeguard against supply chain attacks.

We only scan the container image that is used deploying the oneseismic
API. Containers only used for testing and thus not permanently used are
currently not scanned to save resoruces.

[1]: https://github.com/aquasecurity/trivy
[2]: https://github.com/aquasecurity/trivy-action
[3]: https://docs.github.com/en/actions/reference/security/secure-use#using-third-party-actions
@ajaust

ajaust commented Nov 4, 2025

Copy link
Copy Markdown
Contributor Author

Nevermind. This should have been in my fork... Closing the PR.

@ajaust ajaust closed this Nov 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant