Skip to content

Add lhotari/sandboxed-trivy-action v1.0.0#582

Open
lhotari wants to merge 1 commit intoapache:mainfrom
lhotari:lh-sandboxed-trivy-action-v1.0.0
Open

Add lhotari/sandboxed-trivy-action v1.0.0#582
lhotari wants to merge 1 commit intoapache:mainfrom
lhotari:lh-sandboxed-trivy-action-v1.0.0

Conversation

@lhotari
Copy link
Member

@lhotari lhotari commented Mar 24, 2026

Request for adding a new GitHub Action to the allow list

Overview

This action is forked from aquasecurity/trivy-action with security hardened by running Trivy inside a sandboxed Docker container. More details about the security hardening in the README file of the repository.
Credits to Aqua Security for the original action.

Name of action:
lhotari/sandboxed-trivy-action

URL of action:
https://github.com/lhotari/sandboxed-trivy-action
https://github.com/marketplace/actions/sandboxed-trivy

Version to pin to (hash only):
f5a39c678492e26ad3b2dc52edf1b638771401b5

Permissions

No special permissions required.

Related Actions

This is a fork of https://github.com/aquasecurity/trivy-action

Checklist

You should be able to check most of these boxes for an action to be considered for review.
Please check all boxes that currently apply:

  • The action is listed in the GitHub Actions Marketplace
  • The action is not already on the list of approved actions
  • The action has a sufficient number of contributors or has contributors within the ASF community
  • The action has a clearly defined license
  • The action is actively developed or maintained
  • The action has CI/unit tests configured

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant