mirror of
https://github.com/krkn-chaos/krkn.git
synced 2026-09-08 09:47:17 +00:00
* adding member request information Signed-off-by: Paige Patton <prubenda@redhat.com> Assisted By: Claude Code: fixes krkn source dependencies cves Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> introduced grype scan on github images Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> golang downgrade Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> golang dependency pinning Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> golang dependency pinning Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> setuptools downgrade Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> go-ntlmssp downgrade Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> security scan in summary Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> setuptools downgrade Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> upgrade to fedora 45 Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> golang dependencies Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> removed pinned dependencies Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> pinned dependency for oc latest Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> golang stdlib stable version Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> upgrading oc release Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> upgrading yq Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> yq build in pipeline Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> pinned transitive dependencies Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> removed not working Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> buildkit unpinned Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> other pinned dependencies Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> other pinned Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> other pinned Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> go work vendor Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> other pinned Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> pin buildkit and distribution Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> reinstated distribution Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> nit Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> SECURITY.md Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> feat: add Grype security scanning badge and comprehensive security policy - Add security badge job to docker-image workflow - Generates detailed badge showing C:X H:Y M:Z vulnerability counts - Runs on every push to main branch - Publishes badge to krkn-lib-docs repository - Uses Grype to scan container image for CVEs - Dynamic color based on severity (green/yellow/orange/red) - Add security badge to README.md - Displays current vulnerability baseline - Placed after coverage badge for visibility - Enhance SECURITY.md with CNCF-ready security policy - Document proactive security approach with Grype CI/CD integration - Define security baseline: 0 Critical, 7 High, 3 Medium, 0 Low (12 total) - Detail accepted risks with mitigation strategies - Document all 12 known CVEs in transitive dependencies - Explain why each CVE cannot be fixed (dependency constraints) - Establish quarterly review process for accepted risks - Add SLA commitments for vulnerability remediation Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com> fix: remove moby/buildkit v0.28.1 pin that breaks oc build The moby/buildkit v0.28.1 upgrade has breaking API changes (undefined: archive.Compression) that are incompatible with docker/docker v28.5.2 vendored in oc. This CVE is documented as accepted risk in SECURITY.md. Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com> DCO krkn-lib update krkn-lib update * increased krkn-lib version Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> --------- Signed-off-by: Tullio Sebastiani <tsebasti@redhat.com> Co-authored-by: Paige Patton <prubenda@redhat.com>
Kraken image
Container image gets automatically built by quay.io at Kraken image.
Run containerized version
Refer instructions for information on how to run the containerized version of kraken.
Run Custom Kraken Image
Refer to instructions for information on how to run a custom containerized version of kraken using podman.