Skip to content

ci: Add Trivy vulnerability scanner for docker images - #372

Merged
markometcalfe merged 3 commits into
totara:masterfrom
markometcalfe:setup-trivy-scanning
Nov 24, 2025
Merged

markometcalfe merged 3 commits into
totara:masterfrom
markometcalfe:setup-trivy-scanning

Conversation

@markometcalfe

@markometcalfe markometcalfe commented Nov 23, 2025 •

Copy link
Copy Markdown
Contributor

Description

This sets a Trivy vulnerability scanner for the repo and docker images.
It is set up to run on a schedule of every Monday at 6am (NZST).
It will raise any critical or high level vulnerabilities in the security tab.

image

Testing Instructions

Nothing to be tested before merging

Checklist

  • Does what the author says it will do
  • Testing instructions are provided
  • Commit messages make sense and follow the conventional commit standard
  • No identified security issues
  • No identified maintenance issues
  • Any third-party libraries/dependencies use the MIT or Apache 2.0 license
  • Changes made are backwards compatible and will not break existing setups
  • Changes to scripts in the bin/ directory run correctly on both MacOS and WSL
  • Changes to containers can be built locally sucessfully (e.g. via tbuild container && tup container)
  • Containers/images are compatible with both AMD64 (Windows) and ARM64 (MacOS)
  • Changes made to config.php are compatible with our oldest supported Totara version, our newest Totara version, and Moodle

@github-advanced-security

Copy link
Copy Markdown

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

@LinnyTheDuck LinnyTheDuck left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@markometcalfe
markometcalfe merged commit 3875ab8 into totara:master Nov 24, 2025
21 of 22 checks passed
@markometcalfe
markometcalfe deleted the setup-trivy-scanning branch November 24, 2025 00:04
@TotaraAdmin

Copy link
Copy Markdown

🎉 This PR is included in version 1.22.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants