如何使用Trivy GitHub Action扫描GitHub Packages私有镜像?
扫描GitHub Packages私有Docker镜像的Trivy Action配置问题解决
问题描述
尝试使用Trivy GitHub Action扫描GitHub Packages中的私有Docker镜像,先后尝试两种配置均失败,报错核心为远程镜像拉取未授权以及本地无对应镜像。
第一种尝试的Action配置:
jobs: security: runs-on: ubuntu-24.04 permissions: contents: read packages: read steps: - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@0.32.0 with: image-ref: ghcr.io/${{ github.repository }}:${{ github.ref_name }} format: github ignore-unfixed: false github-pat: ${{ secrets.GITHUB_TOKEN }}
第二种尝试的配置:
steps: - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@0.32.0 with: image-ref: ghcr.io/${{ github.repository }}:${{ github.ref_name }} format: github ignore-unfixed: false env: TRIVY_USERNAME: ${{ github.repository_owner }} TRIVY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
收到的报错信息:
2025-07-09T13:11:44Z FATAL Fatal error run error: image scan error: scan error: unable to initialize a scan service: unable to initialize an image scan service: unable to find the specified image "ghcr.io/org/repo:2025.12" in ["docker" "containerd" "podman" "remote"]: 4 errors occurred: * docker error: unable to inspect the image (ghcr.io/org/repo:2025.12): Error response from daemon: No such image: ghcr.io/org/repo:2025.12 * containerd error: failed to list images from containerd client: connection error: desc = "transport: Error while dialing: dial unix /run/containerd/containerd.sock: connect: permission denied" * podman error: unable to initialize Podman client: no podman socket found: stat /run/user/1001/podman/podman.sock: no such file or directory * remote error: GET https://ghcr.io/token?scope=repository%3Aorg%2Frepo%3Apull&service=ghcr.io: UNAUTHORIZED: authentication required Error: Process completed with exit code 1.
解决方案
1. 提前登录GHCR并拉取镜像到本地
Trivy远程扫描模式的授权配置易出问题,最可靠的方式是先将镜像拉取到Runner本地再扫描,在Trivy步骤前添加登录和拉取操作:
jobs: security: runs-on: ubuntu-24.04 permissions: contents: read packages: read steps: - name: Log in to GitHub Container Registry uses: docker/login-action@v3 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Pull target image run: docker pull ghcr.io/${{ github.repository }}:${{ github.ref_name }} - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@0.32.0 with: image-ref: ghcr.io/${{ github.repository }}:${{ github.ref_name }} format: github ignore-unfixed: false
2. 验证权限配置
- 确保
permissions块中的packages: read已正确设置,默认GITHUB_TOKEN需要该权限才能拉取私有镜像 - 若使用自定义个人访问令牌(PAT)替代默认
GITHUB_TOKEN,需确保PAT拥有read:packages权限
3. 核对镜像标签
确认${{ github.ref_name }}对应的分支名或标签与GHCR上存在的镜像标签完全一致,避免因标签不存在导致拉取失败
内容的提问来源于stack exchange,提问作者Sig
相关产品推荐
相关产品推荐

