← docsSecurity

/performing-container-security-scanning-with-trivy

Run comprehensive Trivy-based container security scanning across images, filesystem source.

Run comprehensive Trivy-based container security scanning across images, filesystem sources, and configuration artifacts with policy-driven enforcement outputs.

Category

Security

Execution

6 steps, sequential + gated

Goal

Run comprehensive Trivy-based container security scanning across images, filesystem sources, and configuration artifacts with policy-driven enforcement outputs.

Scope

Applies to

  • +Run full Trivy container security scan
  • +Scan image/filesystem/manifests with Trivy
  • +Generate SBOM and security findings from container artifacts

Does not cover

  • −Trivial changes outside the workflow domain

Triggers

"Run full Trivy container security scan""Scan image/filesystem/manifests with Trivy""Generate SBOM and security findings from container artifacts""Apply Trivy scanning in security verification flow"

Inputs

  • →Context: environment/system affected
  • →Scope: change boundary
  • →Constraints: policy or hard rules

Invariants

  • 01Scan mode and severity policy must be explicit and reproducible.
  • 02Findings above gate threshold must trigger blocking status where enforcement is enabled.
  • 03SBOM and report artifacts must map to target digest/path identity.
  • 04Ignore entries cannot be permanent or unexplained.

Procedure

  1. Step 1Step 1 — **Define scan scope**
  2. Step 2Step 2 — **Execute primary scans**
  3. Step 3Step 3 — **Collect and normalize findings**
  4. Step 4Step 4 — **Generate SBOM**
  5. Step 5Step 5 — **Enforce policy gate**
  6. Step 6Step 6 — **Integrate and publish**

Outputs

  • ▸Consolidated Trivy findings report by target and severity.
  • ▸SBOM artifact tied to scan subject.
  • ▸Gate decision output with remediation priorities.
  • ▸Exception/tuning register updates.

Review Gate

  • [ ]Scan coverage includes all required target classes.
  • [ ]Blocking threshold findings are enforced consistently.
  • [ ]SBOM and findings artifacts are traceable and retained.
  • [ ]Exception handling is justified and time-bounded.
  • [ ]Output is ready for downstream triage automation.