/performing-container-security-scanning-with-trivy
Run comprehensive Trivy-based container security scanning across images, filesystem source.
Run comprehensive Trivy-based container security scanning across images, filesystem sources, and configuration artifacts with policy-driven enforcement outputs.
Category
Security
Execution
6 steps, sequential + gated
Goal
Run comprehensive Trivy-based container security scanning across images, filesystem sources, and configuration artifacts with policy-driven enforcement outputs.
Scope
Applies to
- +Run full Trivy container security scan
- +Scan image/filesystem/manifests with Trivy
- +Generate SBOM and security findings from container artifacts
Does not cover
- −Trivial changes outside the workflow domain
Triggers
"Run full Trivy container security scan""Scan image/filesystem/manifests with Trivy""Generate SBOM and security findings from container artifacts""Apply Trivy scanning in security verification flow"
Inputs
- →Context: environment/system affected
- →Scope: change boundary
- →Constraints: policy or hard rules
Invariants
- 01Scan mode and severity policy must be explicit and reproducible.
- 02Findings above gate threshold must trigger blocking status where enforcement is enabled.
- 03SBOM and report artifacts must map to target digest/path identity.
- 04Ignore entries cannot be permanent or unexplained.
Procedure
- Step 1Step 1 — **Define scan scope**
- Step 2Step 2 — **Execute primary scans**
- Step 3Step 3 — **Collect and normalize findings**
- Step 4Step 4 — **Generate SBOM**
- Step 5Step 5 — **Enforce policy gate**
- Step 6Step 6 — **Integrate and publish**
Outputs
- ▸Consolidated Trivy findings report by target and severity.
- ▸SBOM artifact tied to scan subject.
- ▸Gate decision output with remediation priorities.
- ▸Exception/tuning register updates.
Review Gate
- [ ]Scan coverage includes all required target classes.
- [ ]Blocking threshold findings are enforced consistently.
- [ ]SBOM and findings artifacts are traceable and retained.
- [ ]Exception handling is justified and time-bounded.
- [ ]Output is ready for downstream triage automation.