sca-trivy

Community

Secure containers with Trivy-based SCA.

Authorrohunj
Version1.0.0
Installs0

System Documentation

What problem does it solve?

Software supply chain and container security require continuous scanning of images, dependencies, and IaC to identify CVEs, misconfigurations, and license risks, which this skill automates using Trivy.

Core Features & Use Cases

  • SCA and container vulnerability scanning for CVEs and misconfigurations across languages and ecosystems.
  • SBOM generation in CycloneDX or SPDX formats and CI/CD integration with SARIF outputs.
  • Prioritized remediation guidance based on CVSS and exploitability across Terraform, Kubernetes, Dockerfiles, and container images.

Quick Start

Run a Trivy-based security scan of your container image, dependencies, and IaC to generate a prioritized remediation report.

Dependency Matrix

Required Modules

None required

Components

scriptsreferencesassets

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: sca-trivy
Download link: https://github.com/rohunj/claude-build-workflow/archive/main.zip#sca-trivy

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.