← docsSecurity

/scanning-containers-with-trivy-in-cicd

Implement a CI/CD-native container scanning workflow using Trivy that blocks vulnerable im.

Implement a CI/CD-native container scanning workflow using Trivy that blocks vulnerable images and misconfigurations from promotion based on deterministic severity gates.

Category

Security

Execution

9 steps, sequential + gated

Goal

Implement a CI/CD-native container scanning workflow using Trivy that blocks vulnerable images and misconfigurations from promotion based on deterministic severity gates.

Scope

Applies to

  • +Add Trivy scan to CI/CD pipeline
  • +Block container releases with critical/high CVEs
  • +Generate SBOM and gate image promotion

Does not cover

  • −Trivial changes outside the workflow domain

Triggers

"Add Trivy scan to CI/CD pipeline""Block container releases with critical/high CVEs""Generate SBOM and gate image promotion""Scan Dockerfiles/manifests in pull requests"

Inputs

  • →Context: environment/system affected
  • →Scope: change boundary
  • →Constraints: policy or hard rules

Invariants

  • 01No image promotion to protected environments without a successful scan gate.
  • 02Severity gate policy is explicit and versioned in pipeline configuration.
  • 03Ignore/exception entries must include rationale and expiry.
  • 04Scan artifacts must be retained for auditing and trend analysis.
  • 05Trivy DB freshness/caching policy must be explicit to avoid stale assessments.

Procedure

  1. Step 1Step 1 — **Define policy and gate behavior**
  2. Step 2Step 2 — **Build image deterministically**
  3. Step 3Step 3 — **Run vulnerability scan on image**
  4. Step 4Step 4 — **Run misconfiguration scan**
  5. Step 5Step 5 — **Apply exception policy**
  6. Step 6Step 6 — **Generate SBOM and optional secondary checks**
  7. Step 7Step 7 — **Cache and resilience controls**
  8. Step 8Step 8 — **Aggregate and enforce gate**
  9. Step 9Step 9 — **Verification and reporting**

Outputs

  • ▸CI/CD pipeline steps for Trivy image/config scanning.
  • ▸Vulnerability scan reports (JSON/SARIF/table as configured).
  • ▸SBOM artifact for scanned image.
  • ▸Gate decision summary (`PASS`/`FAIL`) with actionable findings.
  • ▸Exception register entries with rationale and expiration.

Review Gate

  • [ ]Image scan blocks findings above configured severity threshold.
  • [ ]Misconfiguration scan enforces the same policy rigor as image scan.
  • [ ]SBOM is generated and retained for audited builds.
  • [ ]Exception handling is traceable and time-bounded.
  • [ ]Pipeline blocks promotion when gate fails.