Skip to content

Security: weekly Trivy scan CI for all 20 module Docker images #4

@RedjiJB

Description

@RedjiJB

Add automated weekly Trivy container security scans across all 20 module repos.\n1. Create/update .github/workflows/security.yml in each module repo to include aquasecurity/trivy-action on a weekly cron schedule\n2. Upload SARIF results to GitHub Advanced Security tab\n3. Set exit-code: 1 for CRITICAL severity to block releases on critical CVEs\n4. Add a summary badge to each module repo README\nNote: Workflows already scaffolded in all 20 repos — update severity and schedule fields only.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions