Trivy Security Scan #2
trivy.yml
on: schedule
Matrix: Trivy Image Scan
Secret Detection (Gitleaks)
5s
Ansible Lint
35s
Trivy Filesystem / Config Scan
13s
Notify Scan Results
2s
Annotations
53 errors and 26 warnings
|
Secret Detection (Gitleaks)
🛑 missing gitleaks license. Go grab one at gitleaks.io and store it as a GitHub Secret named GITLEAKS_LICENSE. For more info about the recent breaking update, see [here](https://github.com/gitleaks/gitleaks-action#-announcement).
|
|
Trivy Filesystem / Config Scan
Path does not exist: trivy-fs.sarif
|
|
Trivy Filesystem / Config Scan
Process completed with exit code 1.
|
|
Trivy Image Scan (quay.io/keycloak/keycloak:26, keycloak)
Path does not exist: trivy-keycloak.sarif
|
|
Trivy Image Scan (quay.io/keycloak/keycloak:26, keycloak)
Process completed with exit code 1.
|
|
Trivy Image Scan (freeipa/freeipa-server:fedora-41, freeipa)
Path does not exist: trivy-freeipa.sarif
|
|
Trivy Image Scan (freeipa/freeipa-server:fedora-41, freeipa)
Process completed with exit code 1.
|
|
Trivy Image Scan (postgres:16-alpine, postgresql)
Path does not exist: trivy-postgresql.sarif
|
|
Trivy Image Scan (postgres:16-alpine, postgresql)
Process completed with exit code 1.
|
|
Trivy Image Scan (openkm/openkm:community, openkm)
Path does not exist: trivy-openkm.sarif
|
|
Trivy Image Scan (openkm/openkm:community, openkm)
Process completed with exit code 1.
|
|
Trivy Image Scan (traefik:v3, traefik)
Path does not exist: trivy-traefik.sarif
|
|
Trivy Image Scan (traefik:v3, traefik)
Process completed with exit code 1.
|
|
Trivy Image Scan (mattermost/mattermost-team-edition:9, mattermost)
Path does not exist: trivy-mattermost.sarif
|
|
Trivy Image Scan (mattermost/mattermost-team-edition:9, mattermost)
Process completed with exit code 1.
|
|
Trivy Image Scan (jitsi/web:stable-9457, jitsi)
Path does not exist: trivy-jitsi.sarif
|
|
Trivy Image Scan (jitsi/web:stable-9457, jitsi)
Process completed with exit code 1.
|
|
Trivy Image Scan (taigaio/taiga-front:latest, taiga)
Path does not exist: trivy-taiga.sarif
|
|
Trivy Image Scan (taigaio/taiga-front:latest, taiga)
Process completed with exit code 1.
|
|
Trivy Image Scan (zabbix/zabbix-server-pgsql:ubuntu-7.0-latest, zabbix)
Path does not exist: trivy-zabbix.sarif
|
|
Trivy Image Scan (zabbix/zabbix-server-pgsql:ubuntu-7.0-latest, zabbix)
Process completed with exit code 1.
|
|
Trivy Image Scan (graylog/graylog:6.0, graylog)
Path does not exist: trivy-graylog.sarif
|
|
Trivy Image Scan (graylog/graylog:6.0, graylog)
Process completed with exit code 1.
|
|
Trivy Image Scan (flaviostutz/asterisk:latest, freepbx)
Path does not exist: trivy-freepbx.sarif
|
|
Trivy Image Scan (flaviostutz/asterisk:latest, freepbx)
Process completed with exit code 1.
|
|
Trivy Image Scan (suitecrm/suitecrm:latest, suitecrm)
Path does not exist: trivy-suitecrm.sarif
|
|
Trivy Image Scan (suitecrm/suitecrm:latest, suitecrm)
Process completed with exit code 1.
|
|
Trivy Image Scan (redis:7-alpine, redis)
Path does not exist: trivy-redis.sarif
|
|
Trivy Image Scan (redis:7-alpine, redis)
Process completed with exit code 1.
|
|
Trivy Image Scan (iredmail/iredmail:stable, iredmail)
Path does not exist: trivy-iredmail.sarif
|
|
Trivy Image Scan (iredmail/iredmail:stable, iredmail)
Process completed with exit code 1.
|
|
yaml[colons]:
roles/common/defaults/main.yml#L10
Too many spaces after colon
|
|
var-naming[no-role-prefix]:
roles/common/defaults/main.yml#L10
Variables names from within roles should use common_ as a prefix. (vars: ssh_pubkey_authentication)
|
|
var-naming[no-role-prefix]:
roles/common/defaults/main.yml#L9
Variables names from within roles should use common_ as a prefix. (vars: ssh_password_authentication)
|
|
yaml[colons]:
roles/common/defaults/main.yml#L8
Too many spaces after colon
|
|
var-naming[no-role-prefix]:
roles/common/defaults/main.yml#L8
Variables names from within roles should use common_ as a prefix. (vars: ssh_permit_root_login)
|
|
yaml[colons]:
roles/common/defaults/main.yml#L7
Too many spaces after colon
|
|
var-naming[no-role-prefix]:
roles/common/defaults/main.yml#L7
Variables names from within roles should use common_ as a prefix. (vars: ssh_port)
|
|
yaml[colons]:
roles/common/defaults/main.yml#L6
Too many spaces after colon
|
|
var-naming[no-role-prefix]:
roles/common/defaults/main.yml#L6
Variables names from within roles should use common_ as a prefix. (vars: system_locale)
|
|
var-naming[no-role-prefix]:
roles/common/defaults/main.yml#L5
Variables names from within roles should use common_ as a prefix. (vars: system_timezone)
|
|
Trivy Image Scan (docker.elastic.co/elasticsearch/elasticsearch:8.15.0, elasticsearch)
Path does not exist: trivy-elasticsearch.sarif
|
|
Trivy Image Scan (docker.elastic.co/elasticsearch/elasticsearch:8.15.0, elasticsearch)
Process completed with exit code 1.
|
|
Trivy Image Scan (nextcloud:30-apache, nextcloud)
Path does not exist: trivy-nextcloud.sarif
|
|
Trivy Image Scan (nextcloud:30-apache, nextcloud)
Process completed with exit code 1.
|
|
Trivy Image Scan (glpi/glpi:latest, glpi)
Path does not exist: trivy-glpi.sarif
|
|
Trivy Image Scan (glpi/glpi:latest, glpi)
Process completed with exit code 1.
|
|
Trivy Image Scan (snipe/snipe-it:latest, snipeit)
Path does not exist: trivy-snipeit.sarif
|
|
Trivy Image Scan (snipe/snipe-it:latest, snipeit)
Process completed with exit code 1.
|
|
Trivy Image Scan (zammad/zammad-docker-compose:latest, zammad)
Path does not exist: trivy-zammad.sarif
|
|
Trivy Image Scan (zammad/zammad-docker-compose:latest, zammad)
Process completed with exit code 1.
|
|
Trivy Image Scan (odoo:17, odoo)
Path does not exist: trivy-odoo.sarif
|
|
Trivy Image Scan (odoo:17, odoo)
Process completed with exit code 1.
|
|
Secret Detection (Gitleaks)
Unexpected input(s) 'args', valid inputs are ['']
|
|
Trivy Filesystem / Config Scan
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (quay.io/keycloak/keycloak:26, keycloak)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (freeipa/freeipa-server:fedora-41, freeipa)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (postgres:16-alpine, postgresql)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (openkm/openkm:community, openkm)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (traefik:v3, traefik)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (mattermost/mattermost-team-edition:9, mattermost)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (jitsi/web:stable-9457, jitsi)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (taigaio/taiga-front:latest, taiga)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (zabbix/zabbix-server-pgsql:ubuntu-7.0-latest, zabbix)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (graylog/graylog:6.0, graylog)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (flaviostutz/asterisk:latest, freepbx)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (suitecrm/suitecrm:latest, suitecrm)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (redis:7-alpine, redis)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (iredmail/iredmail:stable, iredmail)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
yaml[line-length]:
roles/suitecrm/tasks/keycloak-saml.yml#L75
Line too long (233 > 160 characters)
|
|
yaml[line-length]:
roles/keycloak/tasks/oidc-clients.yml#L108
Line too long (173 > 160 characters)
|
|
yaml[line-length]:
roles/freeipa/tasks/configure.yml#L42
Line too long (166 > 160 characters)
|
|
yaml[line-length]:
roles/elasticsearch/tasks/install.yml#L12
Line too long (161 > 160 characters)
|
|
Trivy Image Scan (docker.elastic.co/elasticsearch/elasticsearch:8.15.0, elasticsearch)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (nextcloud:30-apache, nextcloud)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (glpi/glpi:latest, glpi)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (snipe/snipe-it:latest, snipeit)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (zammad/zammad-docker-compose:latest, zammad)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy Image Scan (odoo:17, odoo)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|