You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Trivy GitHub Action扫描GitHub Packages私有镜像?

扫描GitHub Packages私有Docker镜像的Trivy Action配置问题解决

问题描述

尝试使用Trivy GitHub Action扫描GitHub Packages中的私有Docker镜像,先后尝试两种配置均失败,报错核心为远程镜像拉取未授权以及本地无对应镜像。

第一种尝试的Action配置:

jobs:
  security:
    runs-on: ubuntu-24.04

    permissions:
      contents: read
      packages: read

    steps:          
      - name: Run Trivy vulnerability scanner
        uses: aquasecurity/trivy-action@0.32.0
        with:
          image-ref: ghcr.io/${{ github.repository }}:${{ github.ref_name }}
          format: github
          ignore-unfixed: false
          github-pat: ${{ secrets.GITHUB_TOKEN }} 

第二种尝试的配置:

steps:          
      - name: Run Trivy vulnerability scanner
        uses: aquasecurity/trivy-action@0.32.0
        with:
          image-ref: ghcr.io/${{ github.repository }}:${{ github.ref_name }}
          format: github
          ignore-unfixed: false 
        env:
          TRIVY_USERNAME: ${{ github.repository_owner }}
          TRIVY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}

收到的报错信息:

2025-07-09T13:11:44Z    FATAL   Fatal error run error: image scan error: scan error: unable to initialize a scan service: unable to initialize an image scan service: unable to find the specified image "ghcr.io/org/repo:2025.12" in ["docker" "containerd" "podman" "remote"]: 4 errors occurred:
    * docker error: unable to inspect the image (ghcr.io/org/repo:2025.12): Error response from daemon: No such image: ghcr.io/org/repo:2025.12
    * containerd error: failed to list images from containerd client: connection error: desc = "transport: Error while dialing: dial unix /run/containerd/containerd.sock: connect: permission denied"
    * podman error: unable to initialize Podman client: no podman socket found: stat /run/user/1001/podman/podman.sock: no such file or directory
    * remote error: GET https://ghcr.io/token?scope=repository%3Aorg%2Frepo%3Apull&service=ghcr.io: UNAUTHORIZED: authentication required
Error: Process completed with exit code 1.

解决方案

1. 提前登录GHCR并拉取镜像到本地

Trivy远程扫描模式的授权配置易出问题,最可靠的方式是先将镜像拉取到Runner本地再扫描,在Trivy步骤前添加登录和拉取操作:

jobs:
  security:
    runs-on: ubuntu-24.04
    permissions:
      contents: read
      packages: read

    steps:
      - name: Log in to GitHub Container Registry
        uses: docker/login-action@v3
        with:
          registry: ghcr.io
          username: ${{ github.actor }}
          password: ${{ secrets.GITHUB_TOKEN }}

      - name: Pull target image
        run: docker pull ghcr.io/${{ github.repository }}:${{ github.ref_name }}

      - name: Run Trivy vulnerability scanner
        uses: aquasecurity/trivy-action@0.32.0
        with:
          image-ref: ghcr.io/${{ github.repository }}:${{ github.ref_name }}
          format: github
          ignore-unfixed: false

2. 验证权限配置

  • 确保permissions块中的packages: read已正确设置,默认GITHUB_TOKEN需要该权限才能拉取私有镜像
  • 若使用自定义个人访问令牌(PAT)替代默认GITHUB_TOKEN,需确保PAT拥有read:packages权限

3. 核对镜像标签

确认${{ github.ref_name }}对应的分支名或标签与GHCR上存在的镜像标签完全一致,避免因标签不存在导致拉取失败

内容的提问来源于stack exchange,提问作者Sig

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 17:23:13