Demo repository showcasing some of the possibilities of Aqua Trivy.
Let's look at an example of scanning an image using Trivy:
> trivy image python:3.4-alpine
The output:
2023-05-06T15:29:29.058Z INFO Need to update DB
2023-05-06T15:29:29.058Z INFO DB Repository: ghcr.io/aquasecurity/trivy-db
2023-05-06T15:29:29.058Z INFO Downloading DB...
36.61 MiB / 36.61 MiB [----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------] 100.00% 9.89 MiB p/s 3.9s
2023-05-06T15:29:34.194Z INFO Vulnerability scanning is enabled
2023-05-06T15:29:34.194Z INFO Secret scanning is enabled
2023-05-06T15:29:34.194Z INFO If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2023-05-06T15:29:34.194Z INFO Please see also https://aquasecurity.github.io/trivy/v0.41/docs/secret/scanning/#recommendation for faster secret detection
2023-05-06T15:29:39.449Z INFO Detected OS: alpine
2023-05-06T15:29:39.450Z INFO Detecting Alpine vulnerabilities...
2023-05-06T15:29:39.450Z INFO Number of language-specific files: 1
2023-05-06T15:29:39.450Z INFO Detecting python-pkg vulnerabilities...
2023-05-06T15:29:39.452Z WARN This OS version is no longer supported by the distribution: alpine 3.9.2
2023-05-06T15:29:39.452Z WARN The vulnerability detection may be insufficient because security updates are not provided
python:3.4-alpine (alpine 3.9.2)
Total: 37 (UNKNOWN: 0, LOW: 4, MEDIUM: 16, HIGH: 13, CRITICAL: 4)
ββββββββββββββββ¬βββββββββββββββββ¬βββββββββββ¬ββββββββββββββββββββ¬ββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Library β Vulnerability β Severity β Installed Version β Fixed Version β Title β
ββββββββββββββββΌβββββββββββββββββΌβββββββββββΌββββββββββββββββββββΌββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β expat β CVE-2018-20843 β HIGH β 2.2.6-r0 β 2.2.7-r0 β expat: large number of colons in input makes parser consume β
β β β β β β high amount... β
β β β β β β https://avd.aquasec.com/nvd/cve-2018-20843 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2019-15903 β β β 2.2.7-r1 β expat: heap-based buffer over-read via crafted XML input β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-15903 β
ββββββββββββββββΌβββββββββββββββββΌβββββββββββΌββββββββββββββββββββΌββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β libbz2 β CVE-2019-12900 β CRITICAL β 1.0.6-r6 β 1.0.6-r7 β bzip2: out-of-bounds write in function BZ2_decompress β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-12900 β
ββββββββββββββββΌβββββββββββββββββΌβββββββββββΌββββββββββββββββββββΌββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β libcrypto1.1 β CVE-2019-1543 β HIGH β 1.1.1a-r1 β 1.1.1b-r1 β openssl: ChaCha20-Poly1305 with long nonces β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-1543 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2020-1967 β β β 1.1.1g-r0 β openssl: Segmentation fault in SSL_check_chain causes denial β
β β β β β β of service β
β β β β β β https://avd.aquasec.com/nvd/cve-2020-1967 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2021-23840 β β β 1.1.1j-r0 β openssl: integer overflow in CipherUpdate β
β β β β β β https://avd.aquasec.com/nvd/cve-2021-23840 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2021-3450 β β β 1.1.1k-r0 β openssl: CA certificate check bypass with β
β β β β β β X509_V_FLAG_X509_STRICT β
β β β β β β https://avd.aquasec.com/nvd/cve-2021-3450 β
β ββββββββββββββββββΌβββββββββββ€ βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2019-1547 β MEDIUM β β 1.1.1d-r0 β openssl: side-channel weak encryption vulnerability β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-1547 β
β ββββββββββββββββββ€ β β ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2019-1549 β β β β openssl: information disclosure in fork() β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-1549 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2019-1551 β β β 1.1.1d-r2 β openssl: Integer overflow in RSAZ modular exponentiation on β
β β β β β β x86_64 β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-1551 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2020-1971 β β β 1.1.1i-r0 β openssl: EDIPARTYNAME NULL pointer de-reference β
β β β β β β https://avd.aquasec.com/nvd/cve-2020-1971 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2021-23841 β β β 1.1.1j-r0 β openssl: NULL pointer dereference in β
β β β β β β X509_issuer_and_serial_hash() β
β β β β β β https://avd.aquasec.com/nvd/cve-2021-23841 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2021-3449 β β β 1.1.1k-r0 β openssl: NULL pointer dereference in signature_algorithms β
β β β β β β processing β
β β β β β β https://avd.aquasec.com/nvd/cve-2021-3449 β
β ββββββββββββββββββΌβββββββββββ€ βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2019-1563 β LOW β β 1.1.1d-r0 β openssl: information disclosure in PKCS7_dataDecode and β
β β β β β β CMS_decrypt_set1_pkey β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-1563 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2021-23839 β β β 1.1.1j-r0 β openssl: incorrect SSLv2 rollback protection β
β β β β β β https://avd.aquasec.com/nvd/cve-2021-23839 β
ββββββββββββββββΌβββββββββββββββββΌβββββββββββ€ βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β libssl1.1 β CVE-2019-1543 β HIGH β β 1.1.1b-r1 β openssl: ChaCha20-Poly1305 with long nonces β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-1543 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2020-1967 β β β 1.1.1g-r0 β openssl: Segmentation fault in SSL_check_chain causes denial β
β β β β β β of service β
β β β β β β https://avd.aquasec.com/nvd/cve-2020-1967 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2021-23840 β β β 1.1.1j-r0 β openssl: integer overflow in CipherUpdate β
β β β β β β https://avd.aquasec.com/nvd/cve-2021-23840 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2021-3450 β β β 1.1.1k-r0 β openssl: CA certificate check bypass with β
β β β β β β X509_V_FLAG_X509_STRICT β
β β β β β β https://avd.aquasec.com/nvd/cve-2021-3450 β
β ββββββββββββββββββΌβββββββββββ€ βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2019-1547 β MEDIUM β β 1.1.1d-r0 β openssl: side-channel weak encryption vulnerability β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-1547 β
β ββββββββββββββββββ€ β β ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2019-1549 β β β β openssl: information disclosure in fork() β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-1549 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2019-1551 β β β 1.1.1d-r2 β openssl: Integer overflow in RSAZ modular exponentiation on β
β β β β β β x86_64 β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-1551 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2020-1971 β β β 1.1.1i-r0 β openssl: EDIPARTYNAME NULL pointer de-reference β
β β β β β β https://avd.aquasec.com/nvd/cve-2020-1971 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2021-23841 β β β 1.1.1j-r0 β openssl: NULL pointer dereference in β
β β β β β β X509_issuer_and_serial_hash() β
β β β β β β https://avd.aquasec.com/nvd/cve-2021-23841 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2021-3449 β β β 1.1.1k-r0 β openssl: NULL pointer dereference in signature_algorithms β
β β β β β β processing β
β β β β β β https://avd.aquasec.com/nvd/cve-2021-3449 β
β ββββββββββββββββββΌβββββββββββ€ βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2019-1563 β LOW β β 1.1.1d-r0 β openssl: information disclosure in PKCS7_dataDecode and β
β β β β β β CMS_decrypt_set1_pkey β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-1563 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2021-23839 β β β 1.1.1j-r0 β openssl: incorrect SSLv2 rollback protection β
β β β β β β https://avd.aquasec.com/nvd/cve-2021-23839 β
ββββββββββββββββΌβββββββββββββββββΌβββββββββββΌββββββββββββββββββββΌββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β musl β CVE-2019-14697 β CRITICAL β 1.1.20-r4 β 1.1.20-r5 β musl libc through 1.1.23 has an x87 floating-point stack β
β β β β β β adjustment im ...... β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-14697 β
β ββββββββββββββββββΌβββββββββββ€ βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2020-28928 β MEDIUM β β 1.1.20-r6 β In musl libc through 1.2.1, wcsnrtombs mishandles particular β
β β β β β β combinati ... β
β β β β β β https://avd.aquasec.com/nvd/cve-2020-28928 β
ββββββββββββββββΌβββββββββββββββββΌβββββββββββ€ βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β musl-utils β CVE-2019-14697 β CRITICAL β β 1.1.20-r5 β musl libc through 1.1.23 has an x87 floating-point stack β
β β β β β β adjustment im ...... β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-14697 β
β ββββββββββββββββββΌβββββββββββ€ βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2020-28928 β MEDIUM β β 1.1.20-r6 β In musl libc through 1.2.1, wcsnrtombs mishandles particular β
β β β β β β combinati ... β
β β β β β β https://avd.aquasec.com/nvd/cve-2020-28928 β
ββββββββββββββββΌβββββββββββββββββΌβββββββββββΌββββββββββββββββββββΌββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β sqlite-libs β CVE-2019-8457 β CRITICAL β 3.26.0-r3 β 3.28.0-r0 β sqlite: heap out-of-bound read in function rtreenode() β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-8457 β
β ββββββββββββββββββΌβββββββββββ€ βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2019-19244 β HIGH β β 3.28.0-r2 β sqlite: allows a crash if a sub-select uses both DISTINCT β
β β β β β β and window... β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-19244 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2019-5018 β β β 3.28.0-r0 β sqlite: Use-after-free in window function leading to remote β
β β β β β β code execution β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-5018 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2020-11655 β β β 3.28.0-r3 β sqlite: malformed window-function query leads to DoS β
β β β β β β https://avd.aquasec.com/nvd/cve-2020-11655 β
β ββββββββββββββββββΌβββββββββββ€ βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2019-16168 β MEDIUM β β 3.28.0-r1 β sqlite: Division by zero in whereLoopAddBtreeIndex in β
β β β β β β sqlite3.c β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-16168 β
β ββββββββββββββββββ€ β βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2019-19242 β β β 3.28.0-r2 β sqlite: SQL injection in sqlite3ExprCodeTarget in expr.c β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-19242 β
ββββββββββββββββ΄βββββββββββββββββ΄βββββββββββ΄ββββββββββββββββββββ΄ββββββββββββββββ΄βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
2023-05-06T15:29:39.463Z INFO Table result includes only package filenames. Use '--format json' option to get the full path to the package file.
Python (python-pkg)
Total: 4 (UNKNOWN: 0, LOW: 0, MEDIUM: 2, HIGH: 2, CRITICAL: 0)
βββββββββββββββββββββββββ¬βββββββββββββββββ¬βββββββββββ¬ββββββββββββββββββββ¬ββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Library β Vulnerability β Severity β Installed Version β Fixed Version β Title β
βββββββββββββββββββββββββΌβββββββββββββββββΌβββββββββββΌββββββββββββββββββββΌββββββββββββββββΌββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β pip (METADATA) β CVE-2019-20916 β HIGH β 19.0.3 β 19.2 β python-pip: directory traversal in _download_http_url() β
β β β β β β function in src/pip/_internal/download.py β
β β β β β β https://avd.aquasec.com/nvd/cve-2019-20916 β
β ββββββββββββββββββΌβββββββββββ€ βββββββββββββββββΌββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2021-3572 β MEDIUM β β 21.1 β python-pip: Incorrect handling of unicode separators in git β
β β β β β β references β
β β β β β β https://avd.aquasec.com/nvd/cve-2021-3572 β
βββββββββββββββββββββββββΌβββββββββββββββββ€ βββββββββββββββββββββΌββββββββββββββββΌββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β setuptools (METADATA) β CVE-2022-40897 β β 40.8.0 β 65.5.1 β Regular Expression Denial of Service (ReDoS) in β
β β β β β β package_index.py β
β β β β β β https://avd.aquasec.com/nvd/cve-2022-40897 β
βββββββββββββββββββββββββΌβββββββββββββββββΌβββββββββββΌββββββββββββββββββββΌββββββββββββββββΌββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β wheel (METADATA) β CVE-2022-40898 β HIGH β 0.33.1 β 0.38.1 β remote attackers can cause denial of service via attacker β
β β β β β β controlled input... β
β β β β β β https://avd.aquasec.com/nvd/cve-2022-40898 β
βββββββββββββββββββββββββ΄βββββββββββββββββ΄βββββββββββ΄ββββββββββββββββββββ΄ββββββββββββββββ΄ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
You can scan a Dockerfile by running the Trivy scan on the Dockerfile, e.g., scanning-targets/Dockerfile.
trivy config scanning-targets/Dockerfile
You can also scan a Dockerfile by embedding and running the Trivy scan during the build, e.g., scanning-targets/Dockerfile.
docker build -t scanned-image scanning-targets/
The --exit-code
specifies the exit code when any security issues are found, thus running it with the example from the Dockerfile in scanning-targets/ will fail the Dockerbuild if the status code is 1 (which in this case it is).
The output:
[+] Building 16.2s (5/5) FINISHED => [internal] load build definition from Dockerfile 0.0s => => transferring dockerfile: 262B 0.0s => [internal] load .dockerignore 0.0s => => transferring context: 2B 0.0s => [internal] load metadata for docker.io/library/alpine:3.7 0.6s => CACHED [1/2] FROM docker.io/library/alpine:3.7@sha256:8421d9a84432575381bfabd248f1eb56f3aa21d9d7cd2511583c68c9 0.0s => ERROR [2/2] RUN apk add curl && curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/master/con 15.5s ------ > [2/2] RUN apk add curl && curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/master/contrib/install.sh | sh -s -- -b /usr/local/bin && trivy filesystem --exit-code 1 --no-progress /: #5 0.366 fetch http://dl-cdn.alpinelinux.org/alpine/v3.7/main/x86_64/APKINDEX.tar.gz #5 0.634 fetch http://dl-cdn.alpinelinux.org/alpine/v3.7/community/x86_64/APKINDEX.tar.gz #5 0.778 (1/4) Installing ca-certificates (20190108-r0) #5 0.852 (2/4) Installing libssh2 (1.9.0-r1) #5 0.912 (3/4) Installing libcurl (7.61.1-r3) #5 0.986 (4/4) Installing curl (7.61.1-r3) #5 1.051 Executing busybox-1.27.2-r11.trigger #5 1.056 Executing ca-certificates-20190108-r0.trigger #5 1.119 OK: 6 MiB in 17 packages #5 1.330 aquasecurity/trivy info checking GitHub for latest tag #5 1.892 aquasecurity/trivy info found version: 0.41.0 for v0.41.0/Linux/64bit #5 8.685 aquasecurity/trivy info installed /usr/local/bin/trivy #5 9.131 2023-05-07T07:28:11.532Z INFO Need to update DB #5 9.131 2023-05-07T07:28:11.532Z INFO DB Repository: ghcr.io/aquasecurity/trivy-db #5 9.131 2023-05-07T07:28:11.532Z INFO Downloading DB... #5 14.80 2023-05-07T07:28:17.195Z INFO Vulnerability scanning is enabled #5 14.80 2023-05-07T07:28:17.196Z INFO Secret scanning is enabled #5 14.80 2023-05-07T07:28:17.196Z INFO If your scanning is slow, please try '--scanners vuln' to disable secret scanning #5 14.80 2023-05-07T07:28:17.196Z INFO Please see also https://aquasecurity.github.io/trivy/v0.41/docs/secret/scanning/#recommendation for faster secret detection #5 14.99 2023-05-07T07:28:17.393Z INFO Detected OS: alpine #5 14.99 2023-05-07T07:28:17.393Z INFO Detecting Alpine vulnerabilities... #5 14.99 2023-05-07T07:28:17.394Z INFO Number of language-specific files: 0 #5 14.99 2023-05-07T07:28:17.394Z WARN This OS version is no longer supported by the distribution: alpine 3.7.3 #5 14.99 2023-05-07T07:28:17.394Z WARN The vulnerability detection may be insufficient because security updates are not provided #5 15.00 #5 15.00 localhost (alpine 3.7.3) #5 15.00 ======================== #5 15.00 Total: 2 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 2) #5 15.00 #5 15.00 ββββββββββββββ¬βββββββββββββββββ¬βββββββββββ¬ββββββββββββββββββββ¬ββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ #5 15.00 β Library β Vulnerability β Severity β Installed Version β Fixed Version β Title β #5 15.00 ββββββββββββββΌβββββββββββββββββΌβββββββββββΌββββββββββββββββββββΌββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€ #5 15.00 β musl β CVE-2019-14697 β CRITICAL β 1.1.18-r3 β 1.1.18-r4 β musl libc through 1.1.23 has an x87 floating-point stack β #5 15.00 β β β β β β adjustment im ...... β #5 15.00 β β β β β β https://avd.aquasec.com/nvd/cve-2019-14697 β #5 15.00 ββββββββββββββ€ β β β β β #5 15.00 β musl-utils β β β β β β #5 15.00 β β β β β β β #5 15.00 β β β β β β β #5 15.00 ββββββββββββββ΄βββββββββββββββββ΄βββββββββββ΄ββββββββββββββββββββ΄ββββββββββββββββ΄βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ ------ executor failed running [/bin/sh -c apk add curl && curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/master/contrib/install.sh | sh -s -- -b /usr/local/bin && trivy filesystem --exit-code 1 --no-progress /]: exit code: 1The .github/workflows/trivy-scann.yaml show how to integrate Dockerfile scanning using Trivy and GH Action. You will find the results in the Security tab in GH.
To create a cluster, run the following command:
kind create cluster --name trivy-demo
kind get kubeconfig --name trivy-demo > ~/.kube/config
Following the instructions here to install Trivy using Helm.
k get vulnerabilityreports.aquasecurity.github.io
k get vulnerabilityreports.aquasecurity.github.io {report-name} -o yaml