logo

Securing GitHub Actions with Trivy and Cosign

ID: 0babdec2-c328-5152-8531-a486d7abf1af

STIX ID: report--0babdec2-c328-5152-8531-a486d7abf1af

Feed Name: Aqua Security Blog

Date Published: 2022-02-10

Date Updated: 2026-04-26

...
...

This guide explains how to integrate Trivy vulnerability scanning and Cosign image signing into GitHub Actions CI/CD workflows—covering permission changes, workflow steps to produce and upload SARIF results, and verifying signed images from GitHub Container Registry—to improve container software supply chain security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.