diff --git a/.github/workflows/security-trivy-iac-check.yaml b/.github/workflows/security-trivy-iac-check.yaml deleted file mode 100644 index 4f1afde..0000000 --- a/.github/workflows/security-trivy-iac-check.yaml +++ /dev/null @@ -1,24 +0,0 @@ -name: build - -on: - workflow_call: - -jobs: - build: - name: Build - runs-on: ubuntu-24.04 - steps: - - name: Checkout code - uses: actions/checkout@v7 - - #- name: Run Trivy vulnerability scanner in IaC mode - # uses: aquasecurity/trivy-action@v0.69.2 # This is the version with the fix for the hackerbot-claw incident - # with: - # scan-type: 'config' - # hide-progress: false - # format: 'sarif' - # output: 'trivy-iac-results.sarif' - # exit-code: '0' - # ignore-unfixed: true - # severity: 'CRITICAL,HIGH' - # timeout: '30m' diff --git a/README.md b/README.md index d5d40c7..4fd1d85 100644 --- a/README.md +++ b/README.md @@ -22,7 +22,6 @@ Shared workflows and actions: - [Security](#security) - workflows - [Gitleaks](#gitleaks) - - [Run Trivy IAC with Quality GAte](#run-trivy-iac-with-quality-gate) ## Automation @@ -363,28 +362,4 @@ jobs: shared: uses: dfds/shared-workflows/.github/workflows/security-gitleaks.yml@master secrets: inherit -``` - -### Run Trivy IAC with Quality GAte - -_This is a workflow_ - -This Github Action will run the trivy IAC check and block if High or Critical issues are found. - -[Marketplace](https://github.com/marketplace/actions/run-trivy-iac-check) - -How to invoke this workflow: - -```yaml -name: Run Trivy IAC with Quality GAte - -on: - push: - branches: [ "master", "main" ] - pull_request: - branches: [ "master", "main" ] - -jobs: - shared: - uses: dfds/shared-workflows/.github/workflows/security-trivy-iac-check.yaml@master ``` \ No newline at end of file diff --git a/examples/security-trivy-iac-check.yaml b/examples/security-trivy-iac-check.yaml deleted file mode 100644 index 71ea698..0000000 --- a/examples/security-trivy-iac-check.yaml +++ /dev/null @@ -1,13 +0,0 @@ -name: Run Trivy IAC with Quality GAte -description: This Github Action will run the trivy IAC check and block if High or Critical issues are found. -author: https://github.com/marketplace/actions/run-trivy-iac-check - -on: - push: - branches: [ "master", "main" ] - pull_request: - branches: [ "master", "main" ] - -jobs: - shared: - uses: dfds/shared-workflows/.github/workflows/security-trivy-iac-check.yaml@master \ No newline at end of file