Skip to content

Add vulnerability detection Github Action to scan built docker images #168

@nigelgbanks

Description

@nigelgbanks

@g7morris used Syft and Grype to scan the images for vulnerabilities in response to the log4j issue. Look into how to integrate these tools so checks are performed:

  • For every push if it is a cheap operation.
  • For every release.
  • Perhaps also weekly just incase new vulnerabilities are discovered as the repository doesn't change that often at this point.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions