#!/usr/bin/env sh set -eu # Keep the scanner independent of GitHub-specific composite-action setup. # The release is immutable and the embedded digest is from the official # v0.74.0 checksum manifest. version="0.74.0" archive="trivy_${version}_Linux-64bit.tar.gz" expected_sha256="2ae6fe3ee734b7fdf11335663e18c75ea12dccc76062f09f164a3b0f8be4371a" work_root="${RUNNER_TEMP:-${TMPDIR:-/tmp}}" work_dir="$(mktemp -d "${work_root%/}/pulse-trivy-${version}.XXXXXX")" scan_root="${1:-.}" case "${scan_root}" in -*) echo "scan root must be a directory path, not an option" >&2; exit 2 ;; esac [ -d "${scan_root}" ] || { echo "scan root does not exist: ${scan_root}" >&2; exit 2; } cleanup() { rm -rf -- "${work_dir}" } trap cleanup EXIT HUP INT TERM mkdir -p "${work_dir}" curl --fail --silent --show-error --location \ --output "${work_dir}/${archive}" \ "https://github.com/aquasecurity/trivy/releases/download/v${version}/${archive}" printf '%s %s\n' "${expected_sha256}" "${work_dir}/${archive}" | sha256sum --check --status tar -xzf "${work_dir}/${archive}" -C "${work_dir}" trivy "${work_dir}/trivy" fs \ --scanners vuln \ --include-dev-deps \ --format table \ --severity HIGH,CRITICAL \ --exit-code 1 \ --ignore-unfixed \ --no-progress \ "${scan_root}"