Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[DPE-6365] add trivy to github workflow #45

Merged
merged 9 commits into from
Jan 27, 2025
Merged

Conversation

MiaAltieri
Copy link
Contributor

@MiaAltieri MiaAltieri commented Jan 22, 2025

Issue

No SBOM generation or Code scanning is currently done for our rock

Solution

Add this based on Kafka

Code scanning results

link to code scanning results note many are critical

Since snap is used in the rock, it is not strictly necessary to duplicate this work for snaps and take up more runners than necessary

@github-advanced-security
Copy link

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

Copy link
Contributor

@Mehdi-Bendriss Mehdi-Bendriss left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you Mia! minor comments

.github/workflows/trivy.yaml Outdated Show resolved Hide resolved
.github/workflows/trivy.yaml Outdated Show resolved Hide resolved
.github/workflows/trivy.yaml Outdated Show resolved Hide resolved
.github/workflows/trivy.yaml Show resolved Hide resolved
@MiaAltieri MiaAltieri merged commit 06b32a8 into 6-22.04 Jan 27, 2025
10 checks passed
@MiaAltieri MiaAltieri deleted the DPE-6365-trivy branch January 27, 2025 09:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants