Merge pull request #199 from evrardjp/ci/add-security-scanner

feat: Add security scanning into CI
This commit is contained in:
Daniel Holbach
2020-09-14 14:50:34 +02:00
committed by GitHub
2 changed files with 21 additions and 0 deletions
+7
View File
@@ -0,0 +1,7 @@
general:
bestPracticeViolations:
# We violate this rule because we add kubectl from a remote location
# Instead of building it from source/copying it.
# Until we change our practices (e.g. have Dockerfile build kubectl
# in a multi-staged manner), we should skip this check
- CIS-DI-0009
+14
View File
@@ -0,0 +1,14 @@
# This should not be made a mandatory test
# It is only used to make us aware of any potential security failure, that
# should trigger a bump of the image in build/.
name: "Image vulnerability scan"
on: [push, pull_request]
jobs:
build-and-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@master
- run: make DH_ORG="${{ github.repository_owner }}" VERSION="${{ github.sha }}" image
- uses: Azure/container-scan@v0
with:
image-name: docker.io/${{ github.repository_owner }}/kured:${{ github.sha }}