Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add docker container scanning with grype. #694

Merged
merged 1 commit into from
Jan 2, 2024
Merged

add docker container scanning with grype. #694

merged 1 commit into from
Jan 2, 2024

Conversation

qkaiser
Copy link
Contributor

@qkaiser qkaiser commented Dec 24, 2023

Resolve #409 by introducing docker image scan with Grype using dedicated Github Action.

The build only fails if it finds high or critical severity issues with a fix available. All identified issues are reported using SARIF to Github Code Scanning so maintainers have visibility and can decide whether something needs to be fixed (similar to what's already happening with Dependabot).

@github-advanced-security
Copy link

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

@qkaiser qkaiser force-pushed the grype-testing branch 2 times, most recently from 18a4862 to af2d8ae Compare December 24, 2023 14:20
@qkaiser qkaiser self-assigned this Dec 24, 2023
@qkaiser qkaiser added the dependencies Pull requests that update a dependency file label Dec 24, 2023
@kukovecz kukovecz self-requested a review January 2, 2024 09:13
@kukovecz kukovecz merged commit 38424f1 into main Jan 2, 2024
15 checks passed
@kukovecz kukovecz deleted the grype-testing branch January 2, 2024 09:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

update dependencies & include grype tests in build chain
2 participants