Securing GitHub Actions with Trivy and Cosign
ID: 0babdec2-c328-5152-8531-a486d7abf1af
STIX ID: report--0babdec2-c328-5152-8531-a486d7abf1af
Feed Name: Aqua Security Blog
This guide explains how to integrate Trivy vulnerability scanning and Cosign image signing into GitHub Actions CI/CD workflows—covering permission changes, workflow steps to produce and upload SARIF results, and verifying signed images from GitHub Container Registry—to improve container software supply chain security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
