Q: Your security team discovers that developer container images running in production contain unpatched Critical CVEs and run as root with dangerous capabilities. How do you implement Aqua Trivy in CI/CD pipelines to scan container images and Dockerfiles, block builds with Critical fixable vulnerabilities, and export SARIF reports directly to GitHub Security?
Production guide for integrating Aqua Trivy into CI/CD pipelines to scan container images, Dockerfiles, and Helm charts for CVEs and security misconfigurations with automated build-blocking thresholds.
Want to master this scenario in a live sandbox? KodeKloud's Enterprise GitOps with ArgoCD & Kubernetes Rollouts covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Configure Trivy Container Image Scanning with Severity Filters
Scan newly built container images before pushing to registries:
- Trivy Image Scan: Executed
trivy image --severity HIGH,CRITICAL --ignore-unfixed --exit-code 1 payment-service:latest. - Ignore Unfixed CVEs: Setting
--ignore-unfixedensures the build fails only if a patched version of the vulnerable package actually exists in upstream repositories.
Scan Dockerfile Misconfigurations & Secrets with Trivy Config
Catch insecure container configurations before image compilation:
- Config Scanning: Executed
trivy config ./Dockerfile. - Policy Checks: Trivy checks for compliance against CIS Docker Benchmarks: catching missing
USERinstructions (running as root), exposed sensitive ports, and missing health checks. - Secret Scanning: Scans the repository and image filesystem for leaked API keys, tokens, and private SSH certificates.
Export SARIF Reports & Upload to GitHub Code Scanning
Integrate findings natively into GitHub Advanced Security dashboards:
- SARIF Export: Executed
trivy image --format sarif --output trivy-results.sarif payment-service:latest. - Upload Action: Integrated
github/codeql-action/upload-sarif@v3 with: { sarif_file: 'trivy-results.sarif' }. - GitHub Security Alerts: Vulnerabilities display directly in the GitHub repository's Security tab with remediation advice.
Optimize Trivy Vulnerability Database Caching in CI Runners
Accelerate scanning speed by caching the vulnerability database:
- DB Cache Sharing: Configured CI cache for
~/.cache/trivy, downloading differential DB updates in 4 seconds instead of 45 seconds. - Private Registry Push: Only images that pass 100% of Trivy gates are tagged and pushed to the enterprise container registry.
- Scan container images with trivy image --severity HIGH,CRITICAL --ignore-unfixed --exit-code 1.
- Scan Dockerfiles for CIS benchmark misconfigurations and embedded secrets with trivy config.
- Export findings to SARIF format and upload directly to GitHub Code Scanning.
- Cache the Trivy vulnerability database to keep scans blazing fast (<15 seconds).