|
88 | 88 | fi |
89 | 89 | |
90 | 90 | echo "=== Dev container validation completed! ===" |
| 91 | + |
| 92 | + # Using the custom Trivy Security Scan action from this repository |
| 93 | + - name: Security Scan |
| 94 | + id: security-scan |
| 95 | + uses: smartdatafoundry/income_volatility_pipeline/.github/actions/trivy-security-scan@v1.0.0 |
| 96 | + with: |
| 97 | + image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} |
| 98 | + registry: ${{ env.REGISTRY }} |
| 99 | + severity: 'CRITICAL,HIGH' |
| 100 | + detailed-severity: 'CRITICAL,HIGH,MEDIUM,LOW' |
| 101 | + ignore-unfixed: 'true' |
| 102 | + exit-code: '0' |
| 103 | + artifact-name: 'security-scan-results' |
| 104 | + artifact-retention-days: '30' |
| 105 | + github-token: ${{ secrets.GITHUB_TOKEN }} |
| 106 | + post-pr-comment: 'true' |
| 107 | + |
| 108 | + # Optional: Handle scan results programmatically |
| 109 | + - name: Process scan results |
| 110 | + run: | |
| 111 | + echo "Security scan status: ${{ steps.security-scan.outputs.scan-status }}" |
| 112 | + echo "Vulnerabilities found: ${{ steps.security-scan.outputs.vulnerability-count }}" |
| 113 | + echo "Artifact ID: ${{ steps.security-scan.outputs.artifact-id }}" |
| 114 | + |
| 115 | + # You can add custom logic here based on the scan results |
| 116 | + if [ "${{ steps.security-scan.outputs.scan-status }}" = "vulnerabilities_found" ]; then |
| 117 | + echo "⚠️ Security vulnerabilities detected!" |
| 118 | + echo "Consider reviewing the security report before deploying." |
| 119 | + |
| 120 | + # Optionally, you could fail the build for critical vulnerabilities: |
| 121 | + # if [ "${{ steps.security-scan.outputs.vulnerability-count }}" -gt "10" ]; then |
| 122 | + # echo "❌ Too many vulnerabilities found (> 10), failing build" |
| 123 | + # exit 1 |
| 124 | + # fi |
| 125 | + else |
| 126 | + echo "✅ No critical or high severity vulnerabilities found!" |
| 127 | + fi |
91 | 128 |
|
92 | 129 | - name: Container info |
93 | 130 | if: success() |
|
0 commit comments