From 57c76771d46648a0b08cf91172050f6a3a9417bd Mon Sep 17 00:00:00 2001 From: Kelly Thomas Reardon Date: Sun, 10 May 2026 21:45:55 -0500 Subject: [PATCH] adding SAST --- .gitea/workflows/docker-build.yaml | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/.gitea/workflows/docker-build.yaml b/.gitea/workflows/docker-build.yaml index 63097bb..379bb76 100644 --- a/.gitea/workflows/docker-build.yaml +++ b/.gitea/workflows/docker-build.yaml @@ -13,6 +13,20 @@ jobs: - name: Checkout uses: actions/checkout@v4 + - name: Run Trivy vulnerability scanner in repo mode + uses: aquasecurity/trivy-action@v0.36.0 + with: + scan-type: 'fs' + ignore-unfixed: true + format: 'sarif' + output: 'trivy-results.sarif' + severity: 'CRITICAL,HIGH' + + - name: Upload Trivy scan results to GitHub Security tab + uses: github/codeql-action/upload-sarif@v4 + with: + sarif_file: 'trivy-results.sarif' + - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3