scanning-containers-with-trivy-in-cicd

mukul975/scanning-containers-with-trivy-in-cicd · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Integrate Trivy vulnerability scanning into CI/CD pipelines to detect container image CVEs, Dockerfile misconfigurations, and enforce severity-based quality gates.

SKILL.md

Files

This skill is a package of 8 files. Install with the command above, or download the folder.

Related

  1. scanning-docker-images-with-trivy · mukul975 bundle
    Scan Docker images for vulnerabilities, misconfigurations, secrets, and license violations using Trivy, with CI/CD integration and policy enforcement.
    24.6k
    repo stars
  2. implementing-aqua-security-for-container-scanning · mukul975 bundle
    Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.
    24.6k
    repo stars
  3. performing-container-security-scanning-with-trivy · mukul975 bundle
    Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.
    24.6k
    repo stars
  4. scanning-iac-and-images-with-trivy · mukul975 bundle
    Scan container images, IaC, and SBOMs for vulnerabilities and misconfigurations in CI/CD with Trivy.
    24.6k
    repo stars
  5. supply-chain-security · zhaoxuya520 bundle
    Assess software supply chain security by generating SBOMs, scanning dependencies, auditing CI/CD pipelines, analyzing container images, and verifying vulnerability reachability.
    12.8k
    repo stars
  6. building-devsecops-pipeline-with-gitlab-ci · mukul975 bundle
    Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning, dependency scanning, and secret detection.
    24.6k
    repo stars

Frequently asked questions

How do I install the scanning-containers-with-trivy-in-cicd skill?

Run npx skillmds add mukul975/scanning-containers-with-trivy-in-cicd in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the scanning-containers-with-trivy-in-cicd skill do?

Integrate Trivy vulnerability scanning into CI/CD pipelines to detect container image CVEs, Dockerfile misconfigurations, and enforce severity-based quality gates. It is listed under DevOps & Infra, Security, CI/CD, Vulnerability Scanning on SkillMD.

Is scanning-containers-with-trivy-in-cicd safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with scanning-containers-with-trivy-in-cicd?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is scanning-containers-with-trivy-in-cicd free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published scanning-containers-with-trivy-in-cicd?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.