/scanning-containers-with-trivy-in-cicd
Implement a CI/CD-native container scanning workflow using Trivy that blocks vulnerable im.
Implement a CI/CD-native container scanning workflow using Trivy that blocks vulnerable images and misconfigurations from promotion based on deterministic severity gates.
Category
Security
Execution
9 steps, sequential + gated
Goal
Implement a CI/CD-native container scanning workflow using Trivy that blocks vulnerable images and misconfigurations from promotion based on deterministic severity gates.
Scope
Applies to
- +Add Trivy scan to CI/CD pipeline
- +Block container releases with critical/high CVEs
- +Generate SBOM and gate image promotion
Does not cover
- −Trivial changes outside the workflow domain
Triggers
"Add Trivy scan to CI/CD pipeline""Block container releases with critical/high CVEs""Generate SBOM and gate image promotion""Scan Dockerfiles/manifests in pull requests"
Inputs
- →Context: environment/system affected
- →Scope: change boundary
- →Constraints: policy or hard rules
Invariants
- 01No image promotion to protected environments without a successful scan gate.
- 02Severity gate policy is explicit and versioned in pipeline configuration.
- 03Ignore/exception entries must include rationale and expiry.
- 04Scan artifacts must be retained for auditing and trend analysis.
- 05Trivy DB freshness/caching policy must be explicit to avoid stale assessments.
Procedure
- Step 1Step 1 — **Define policy and gate behavior**
- Step 2Step 2 — **Build image deterministically**
- Step 3Step 3 — **Run vulnerability scan on image**
- Step 4Step 4 — **Run misconfiguration scan**
- Step 5Step 5 — **Apply exception policy**
- Step 6Step 6 — **Generate SBOM and optional secondary checks**
- Step 7Step 7 — **Cache and resilience controls**
- Step 8Step 8 — **Aggregate and enforce gate**
- Step 9Step 9 — **Verification and reporting**
Outputs
- ▸CI/CD pipeline steps for Trivy image/config scanning.
- ▸Vulnerability scan reports (JSON/SARIF/table as configured).
- ▸SBOM artifact for scanned image.
- ▸Gate decision summary (`PASS`/`FAIL`) with actionable findings.
- ▸Exception register entries with rationale and expiration.
Review Gate
- [ ]Image scan blocks findings above configured severity threshold.
- [ ]Misconfiguration scan enforces the same policy rigor as image scan.
- [ ]SBOM is generated and retained for audited builds.
- [ ]Exception handling is traceable and time-bounded.
- [ ]Pipeline blocks promotion when gate fails.