| name | scanning-containers-with-trivy-in-cicd |
| description | Use when this skill covers integrating Aqua Security's Trivy scanner into CI/CD pipelines for comprehensive container image vulnerability detection. It addresses scanning Docker images for OS package and application dependency CVEs, detecting misconfigurations in Dockerfiles, scanning filesystem and git repositories, and establishing severity-based quality gates that block deployment of vulnerable images. |
| domain | cybersecurity |
| tags | ["devsecops","cicd","trivy","container-security","vulnerability-scanning","secure-sdlc"] |
| subdomain | devsecops |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.PS-01","GV.SC-07","ID.IM-04","PR.PS-04"] |
Scanning Containers With Trivy In Cicd
Overview
Cybersecurity skill for scanning containers with trivy in cicd. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"scanning containers with trivy in cicd"
-
"This skill covers integrating Aqua Security''s Trivy scanner into CI/CD pipeline"
-
When building Docker container images in CI/CD and needing automated vulnerability scanning before registry push
-
When establishing quality gates that prevent images with critical or high CVEs from reaching production
-
When compliance requirements mandate vulnerability scanning of all container images before deployment
-
When scanning IaC files (Dockerfiles, Kubernetes manifests) alongside container image scanning
-
When needing a single tool to scan OS packages, language-specific dependencies, and misconfigurations
Do not use for runtime container security monitoring (use Falco), for scanning running containers in production (use runtime agents), or when only scanning application source code without containerization (use SAST tools).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Trivy CLI installed (v0.50+) or access to aquasecurity/trivy-action GitHub Action
- Docker daemon available in CI/CD for building and scanning images
- Container registry credentials for pulling base images and pushing scanned images
- Trivy vulnerability database accessible (downloaded automatically or cached)
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: ) -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}