Download PDF version Contact company

Aqua Security, the pure-play cloud native security pioneer, announces that Aqua’s open source Trivy vulnerability scanner is now available as an Aqua Security Trivy GitHub Action. The action integrates with GitHub code scanning so developers can build container image scanning into their GitHub Actions workflow to find and eliminate vulnerabilities before they reach production.

Code scanning was purpose-built with extensibility in mind,” said John Leon, VP of Business Development at GitHub. “We continue to expand our security ecosystem with solutions like Aqua, so developers can work with the security scanning technologies they want, all within the GitHub-native experience they love. Together, we’re making security easier for everyone.”

Actionable security reviews

GitHub code scanning integrates with GitHub Actions or users’ existing CI/CD environments and scans code as it’s created, surfacing actionable security reviews within pull requests and other GitHub experiences.

Developers must avoid deploying images that might harbor significant CVEs that attackers can exploit

The Aqua Security Trivy Action integration finds vulnerabilities (CVEs) in the OS package dependencies and language libraries built into a container image. Developers must avoid deploying images that might harbor significant CVEs that attackers can exploit. The Trivy Action alerts developers to known CVEs via the GitHub user interface to quickly and easily update these dependencies and eliminate the risk.

Ingesting security information

The Trivy Action generates output in a format called SARIF that GitHub supports for ingesting security information. The output from an image scan appears right in the GitHub code scanning UI, specifically under a project repository’s Security tab.

Developers are moving more applications into production, so we’re focused on helping them build securely without slowing down innovation,” said Liz Rice, VP of Open Source Engineering at Aqua. “The new Aqua Security Trivy GitHub Action brings container security scanning right into the GitHub interface that developers know and love.” The new Aqua Security Trivy Action is available on the GitHub Marketplace now. Follow this link to view a sample workflow of building a container image from a Dockerfile in the repository and running the Aqua Security Trivy code scanning over it.

Download PDF version Download PDF version

In case you missed it

Healing Through Innovation: Securing Healthcare In The Cloud
Healing Through Innovation: Securing Healthcare In The Cloud

As the backbone of community welfare, healthcare facilities cater to crucial public needs from emergency care to specialized medical treatments, and due to its position as a signif...

Luxury Londoner Hotel Secured By OPTEX Laser Sensors
Luxury Londoner Hotel Secured By OPTEX Laser Sensors

OPTEX, the pioneering global sensing manufacturer, has specified and installed its compact and intelligent REDSCAN RLS-2020 LiDAR laser sensors at the new luxury five-star Londoner...

ASSA ABLOY eCLIQ: Secure Access At Hofbräuhaus Munich
ASSA ABLOY eCLIQ: Secure Access At Hofbräuhaus Munich

Munich’s Hofbräuhaus enjoys an iconic status, as both a heritage property and a spiritual home for lovers of German beer. “In this historic building is the world&r...