Woodpecker CI plugin with trivy utility to check vulnerabilities in images.
  • Lua 96%
  • Dockerfile 4%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
renovate-bot db4618fde6
All checks were successful
ci/woodpecker/push/change_log Pipeline was successful
ci/woodpecker/push/ci Pipeline was successful
ci/woodpecker/tag/release Pipeline was successful
ci/woodpecker/cron/vulnerability Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
ci/woodpecker/cron/auto_merge Pipeline was successful
ci/woodpecker/cron/release Pipeline was successful
maint: Update docker.io/aquasec/trivy Docker tag to v0.75.0 #71
Merged automatically
2026-10-01 15:30:39 +00:00
lua fix: Do not throw error if file does not exists in file scan (#65) 2026-09-01 19:00:58 +00:00
.gitignore Add file_list mode (#16) 2026-04-15 22:14:52 +00:00
.markdownlint.json Redesign the plugin and give more option (#8) 2026-03-22 23:07:45 +00:00
.prettierrc Redesign the plugin and give more option (#8) 2026-03-22 23:07:45 +00:00
.test.env feat: Refactor to Atis runtime (#42) 2026-08-18 19:27:12 +00:00
.trivyignore fallback to trivy 0.69.3 2026-03-23 19:36:01 +01:00
Containerfile maint: Update docker.io/aquasec/trivy Docker tag to v0.75.0 #71 2026-10-01 15:30:39 +00:00
LICENSE add license 2026-04-11 13:49:42 +02:00
ok_image_list feat: Refactor to Atis runtime (#42) 2026-08-18 19:27:12 +00:00
README.md feat: Add context for the local_fs_scan (#63) 2026-09-01 16:19:19 +00:00
renovate.json ci: Use central renovate.json (#37) 2026-07-19 11:59:33 +00:00

Container with trivy for Woodpecker CI

This is a plugin for Woodpecker CI that check vulnerabilities with trivy utility. This can be used in two mode:

  • Using in pipeline to validate the code itself
  • Using as a cron trigger to scan the repository and belonging container images

In case of repo_scan mode, it open a vulnerability dashboard ticket and update it accordingly. It makes a "ping comment" then a critical one was detected.

In case of scan_file_list each line must contains a fully qualified image name. They will be scanned. The non-vulnerable images are put into an output file.

Usage

It can be used at any event.

Example to use from a release workflow to scan image and local project.

steps:
  - name: Build image locally
    image: code.thinkaboutit.tech/pandora/container-builder.woodpecker
    settings:
      debug: true
      registry_push: false
  - name: Check built image.tar.gz for vulnerabilities
    image: code.thinkaboutit.tech/pandora/trivy.woodpecker
    settings:
      debug: true
  - name: Scan the code of the project
    image: code.thinkaboutit.tech/pandora/trivy.woodpecker
    settings:
      mode: local_fs_scan
      debug: true
  - name: Push the verified image to the repository
    image: code.thinkaboutit.tech/pandora/container-builder.woodpecker
    settings:
      debug: true
      registry_push: true
      registry_push_latest: true
      registry_owner: pandora
      registry_user: bot-ci
      registry_pwd:
        from_secret: gitea-bot-ci

Example to use to scan repository:

steps:
  - name: Check built image.tar.gz for vulnerabilities
    image: code.thinkaboutit.tech/pandora/trivy.woodpecker
    settings:
      mode: repo_scan
      forgejo_user:
        from_secret: ci-user
      forgejo_token:
        from_secret: ci-password
      debug: true

Settings

Base settings

Name Default value Description
mode local_image_scan It can be local_image_scan, local_fs_scan, scan_file_list or repo_scan
repo_name CI_REPO_NAME Name of repository
repo_owner CI_REPO_OWNER Owner of the repository
forgejo_url CI_FORGE_URL Address of Forgejo

File system scan settings

Name Default value Description
file root directory File or directory wants to be scanned

Authentication settings

They are needed when repo_scan is specified.

Name Default value Description
forgejo_user User to handle issues
forgejo_token Access token for CI user

File list settings

They are need when scan_file_list is specified.

Name Default value Description
file_name image_list Name of the file that is read
file_output ok_image_list Images that are not vulnerable
forgejo_user (optional) User to handle issues
forgejo_token (optional) Access token for CI user