> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/security-testing-orchestration/3.0/use-sto/sto-scanner-configuration/trivy/aqua-trivy-scanner-reference.md).

# Aqua Trivy step configuration

With Harness STO, you can use the [Aqua Trivy](https://github.com/aquasecurity/trivy) step to scan:

* [**Container Images**](https://trivy.dev/latest/docs/target/container_image/)
* **Code Repositories** (via [Filesystem](https://trivy.dev/latest/docs/target/filesystem/) scan)
* **SBOM Files** (for both Container Images and Code Repositories)

When scanning code repositories, Trivy performs:

* **Secret Detection** – Identifies hardcoded secrets or sensitive information.
* **Software Composition Analysis (SCA)** – Detects vulnerabilities in open source dependencies.

You can perform these scans using [Orchestration](#scan-mode) or [Ingestion](#scan-mode) modes supported in STO. Follow the steps below for detailed configuration instructions for both scan modes.

{% hint style="info" %}

* You can utilize custom STO scan images and pipelines to run scans as a non-root user. For more details, refer [Configure your pipeline to use STO images from private registry](/security-testing-orchestration/3.0/troubleshooting-and-resources/sto-use-cases/set-up-sto-pipelines/configure-pipeline-to-use-sto-images-from-private-registry.md).
* STO supports three different approaches for loading self-signed certificates. For more information, refer [Run STO scans with custom SSL certificates](/security-testing-orchestration/3.0/troubleshooting-and-resources/sto-use-cases/secure-sto-pipelines/ssl-setup-in-sto.md#supported-workflows-for-adding-custom-ssl-certificates).
  {% endhint %}

### Aqua Trivy step settings <a href="#aqua-trivy-step-settings" id="aqua-trivy-step-settings"></a>

The recommended workflow is to add an AquaTrivy step to a Security Tests or CI Build stage and then configure it as described below.

#### Scan <a href="#scan" id="scan"></a>

**Scan Mode**

**Scan Configuration**

* **Default**: Automatically selected when you choose **Container Image** as the [Target Type](#target). This configuration scans container images for vulnerabilities.
* **Filesystem**: Automatically selected when you choose **Repository** as the [Target Type](#target). This configuration maps to Aqua Trivy’s [Filesystem scan](https://trivy.dev/latest/docs/target/filesystem/) and scans code repositories for vulnerabilities.
* **Trivy SBOM**: Scans an existing SBOM file for vulnerabilities. This configuration supports both **Container Image** and **Repository** as [Target Types](#target).

#### Target <a href="#target" id="target"></a>

**Type**

**Target and Variant Detection**

**Name**

**Variant**

**Workspace**

This field is visible only when you select **Repository** as the Target Type.

Use this field to specify an individual folder or file to scan. For example, if you want to scan a specific file like `/tmp/example/test.py`, set the workspace path to:\
`/harness/tmp/example/test.py`

#### Software Bill of Materials (SBOM) <a href="#software-bill-of-materials-sbom" id="software-bill-of-materials-sbom"></a>

**Generate SBOM**

This option is available only for **Default** and **Filesystem** scan configurations. Enable this field to generate an SBOM for the selected [Target](#target).

**SBOM Format**

Choose the format of the SBOM to generate for the selected [Target](#target): **SPDX** or **CycloneDX**.

#### Container image <a href="#container-image" id="container-image"></a>

**Type**

**Domain**

**Name**

**Tag/Digest**

**Access ID**

**Access Token**

**Region**

**SBOM File**

This field appears only when the **Trivy SBOM** scan configuration is selected. Provide the file path to the SBOM file to scan its components for vulnerabilities.

The following SBOM formats are supported for scanning:

* CycloneDX
* SPDX
* SPDX JSON
* CycloneDX-type attestation
* KBOM (in CycloneDX format)

{% hint style="info" %}
CycloneDX XML format is currently not supported.
{% endhint %}

#### Ingestion <a href="#ingestion" id="ingestion"></a>

**Ingestion File**

#### Log Level <a href="#log-level" id="log-level"></a>

#### Additional CLI flags <a href="#additional-cli-flags" id="additional-cli-flags"></a>

Use this field to run the [`trivy image`](https://aquasecurity.github.io/trivy/v0.49/docs/target/container_image/) scanner with flags such as:

`--ignore-unfixed --scanners vuln`

With these flags, the scanner reports only on vulnerabilities with known fixes.

#### Fail on Severity <a href="#fail-on-severity" id="fail-on-severity"></a>

#### Settings <a href="#settings" id="settings"></a>

#### Additional Configuration <a href="#additional-configuration" id="additional-configuration"></a>

#### Advanced settings <a href="#advanced-settings" id="advanced-settings"></a>

### Configure Aqua Trivy as a Built-in Scanner <a href="#configure-aqua-trivy-as-a-built-in-scanner" id="configure-aqua-trivy-as-a-built-in-scanner"></a>

The Aqua Trivy scanner is available as a [built-in scanner](/security-testing-orchestration/3.0/use-sto/set-up-sto-scans/built-in-scanners.md) in STO. Configuring it as a built-in scanner enables the step to automatically perform scans using the free version without requiring any licenses. Follow these steps to set it up:

1. Search for **Container** in the step palette or navigate to the **Built-in Scanners** section and select the **Container** step.
2. Select **Aqua Trivy** from the list of scanners.
3. Expand the **Additional CLI Flags** section if you want to configure optional CLI flags.
4. Configure the **Container Information** by setting the [Type](#type-1) and [Image](#container-image).
5. Click **Add Scanner** to save the configuration.

The scanner will automatically use the free version, detect scan targets, and can be further configured by clicking on the step whenever needed.

### Proxy settings <a href="#proxy-settings" id="proxy-settings"></a>

### YAML pipeline example <a href="#yaml-pipeline-example" id="yaml-pipeline-example"></a>

Here's an example of the pipeline you created in this tutorial. If you copy this example, replace the placeholder values with appropriate values for your project and organization.

```yaml
pipeline:
  projectIdentifier: YOUR_PROJECT_ID
  orgIdentifier: YOUR_HARNESS_ORG_ID
  tags: {}
  stages:
    - stage:
        name: build
        identifier: build
        type: CI
        spec:
          cloneCodebase: false
          sharedPaths:
            - /var/run
            - /shared/scan_results
          execution:
            steps:
              - step:
                  type: AquaTrivy
                  name: AquaTrivy_1
                  identifier: AquaTrivy_1
                  spec:
                    mode: orchestration
                    config: default
                    target:
                      type: container
                      name: redhat/ubi8-minimal
                      variant: latest
                    advanced:
                      log:
                        level: info
                      args:
                        cli: "--scanners vuln"
                    privileged: true
                    image:
                      type: docker_v2
                      name: redhat/ubi8-minimal
                      domain: docker.io
                      tag: latest
                    sbom:
                      format: spdx-json
          platform:
            os: Linux
            arch: Amd64
          runtime:
            type: Cloud
            spec: {}
          caching:
            enabled: false
            paths: []
          slsa_provenance:
            enabled: false
        description: ""
  identifier: trivyorchestration
  name: trivy-orchestration



```
