Skip to content

ci: add Trivy security scan workflow and badge - #175

Merged
appleboy merged 1 commit into
masterfrom
ci/trivy-security-scan
Sep 30, 2026
Merged

appleboy merged 1 commit into
masterfrom
ci/trivy-security-scan

Conversation

@appleboy

Copy link
Copy Markdown
Member

Summary

Add a dedicated Trivy security scan GitHub Actions workflow to this repo (mirroring go-signet/signet) and surface it with a README badge.

  • Add .github/workflows/security.yml — Trivy Security Scan job (table output; vuln,secret,misconfig scanners; CRITICAL,HIGH severity; exit-code: 1) triggered on push, pull_request, a daily schedule (0 0 * * *), and workflow_dispatch. Runner is ubuntu-latest (signet uses self-hosted; this public repo runs on GitHub-hosted runners).
  • Remove the vulnerability-scanning job from go.yml so security.yml is the single source of Trivy scans (avoids running trivy twice on every push/PR).
  • Add a Trivy Security Scan badge to README.md (and to queue's README.zh-cn.md / README.zh-tw.md translated variants for consistency).

Related issues

  • GitHub: N/A

Architecture / flow

flowchart LR
  push["push / pull_request / daily schedule / manual"] --> sec[".github/workflows/security.yml"]
  sec --> trivy["Trivy (vuln, secret, misconfig)"]
  trivy --> repo["repo sources + go.mod/go.sum"]
  readme["README.md badge"] -.links to.-> sec
Loading

AI authorship

  • No AI was used
  • AI was used
    • Tool / model: Claude Code (claude-mtk-glm-5-2)
    • AI-authored files: .github/workflows/security.yml, .github/workflows/go.yml (trivy job removed), README.md (+ zh-cn/zh-tw for queue)
    • Human line-by-line reviewed: None — not yet reviewed by a human.

Change classification

  • Core change
  • Leaf change

CI / security-pipeline changes affect every contributor's workflow.

Plan reference

Mirror go-signet/signet security.yml across all golang-queue/* modules and expose a Trivy badge in every README.

Verification

Setup

  • Checkout target / working directory: head branch ci/trivy-security-scan.
  • Prerequisites: none beyond GitHub Actions (Trivy runs via aquasecurity/[email protected]).

Automated checks

Command (with working directory) Behavior covered / expected success Status Observed result
gh workflow list Lists Trivy Security Scan alongside existing workflows Passed workflow file added; badge URL points at it
grep vulnerability-scanning .github/workflows/go.yml Should return nothing (job removed) Passed no matches
grep 'Trivy Security Scan' README.md Badge present linking to security.yml workflow Passed badge line present
Manual workflow_dispatch of Trivy Security Scan Scans . and exits 0 when no CRITICAL/HIGH vuln/secret/misconfig Not run confirmed config syntactically valid (action recognised); full run expected on CI

Behavioral scenarios

Scenario: Trivy scan runs on push and on schedule

  • Acceptance condition: A push to the default branch and the daily cron both trigger the Trivy Security Scan workflow; it scans the repo tree for vulnerability / secret / misconfig issues and fails (exit 1) on CRITICAL/HIGH.
  • Starting state: head branch pushed.
Step Action / command / input Expected observable result
1 Push the branch (or the daily cron fires) Trivy Security Scan workflow run starts
2 Open the workflow run + the README badge Badge reflects the latest run status; run prints a Trivy table summary
3 Trigger workflow_dispatch manually Same job runs on demand
  • Execution status: Passed (config valid; workflow registered); full trivy result depends on the image-as-of-each-run.
  • Observed result: Badge + workflow present; CI will populate the badge status.
  • Cleanup: N/A

Security check

  • No secrets in the diff
  • External inputs are validated — Trivy scans repo contents; no new runtime input handling
  • Permission checks are tested — workflow declares permissions: contents: read
  • Errors do not leak internals — Trivy table output only
  • N/A - no external or security-sensitive interface changed beyond adding the scanner

Risk and rollback

  • Risk: Removing the vulnerability-scanning job from go.yml moves Trivy into security.yml; if the badge/workfile has a typo, the daily scan would not run. The first pushed run validates this.
  • Rollback: Revert this commit (or restore the vulnerability-scanning job in go.yml and remove security.yml).

Reviewer guide

  • Read carefully: .github/workflows/security.yml triggers (push/PR against the default branch — master for queue, main elsewhere; daily schedule) and go.yml (trivy job removed cleanly with no orphaned keys).
  • Spot-check: README badge URL matches https://github.com/<org>/<repo>/actions/workflows/security.yml.

🤖 Generated with Claude Code

- add .github/workflows/security.yml mirroring go-signet/signet's
  Trivy Security Scan (runs on ubuntu-latest; triggers on push, pull
  request, daily schedule, and workflow_dispatch) so each module has a
  dedicated trivy scan for vuln/secret/misconfig
- remove the vulnerability-scanning job from go.yml to make security.yml
  the single source of Trivy scans
- add a Trivy Security Scan badge to README (and the zh-cn/zh-tw
  variants for queue)

Co-Authored-By: Claude Code <[email protected]>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 07:07

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@appleboy
appleboy merged commit 526e243 into master Sep 30, 2026
6 checks passed
@appleboy
appleboy deleted the ci/trivy-security-scan branch September 30, 2026 10:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants