feat: add Trivy security scan workflow for vulnerability detection#6
feat: add Trivy security scan workflow for vulnerability detection#6aavinash-nr wants to merge 34 commits into
Conversation
🔒 Trivy Security Scan Results✅ Trivy Security Scanner: No vulnerabilities detected ✅ Trivy scan passed View the complete security scan logs in the Actions tab. |
|
Report Summary ┌──────────────────────────────────────────────────────────────────────────────────┬───────┬─────────────────┬─────────┐
For OSS Maintainers: VEX NoticeIf you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement. To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable. examples/sam/containerized-lambda/nodejs-sam-example/hello-world/package-lock.json (npm)Total: 1 (HIGH: 0, CRITICAL: 1) ┌───────────┬───────────────┬──────────┬────────┬───────────────────┬─────────────────────┬────────────────────────────────────────────────┐ examples/sam/distributedtracing/java/DtSnsFunction/pom.xml (pom)Total: 35 (HIGH: 27, CRITICAL: 8) ┌─────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────────────────────────┬──────────────────────────────────────────────────────────────┐ |
|
Report Summary ┌────────┬───────┬─────────────────┬─────────┐
|
No description provided.