Skip to content

Commit bbf1533

Browse files
committed
Add Trivy Security Scan step to dev container workflow
1 parent 1657e44 commit bbf1533

1 file changed

Lines changed: 37 additions & 0 deletions

File tree

‎.github/workflows/build-devcontainer.yml‎

Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -88,6 +88,43 @@ jobs:
8888
fi
8989
9090
echo "=== Dev container validation completed! ==="
91+
92+
# Using the custom Trivy Security Scan action from this repository
93+
- name: Security Scan
94+
id: security-scan
95+
uses: smartdatafoundry/income_volatility_pipeline/.github/actions/trivy-security-scan@v1.0.0
96+
with:
97+
image-ref: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
98+
registry: ${{ env.REGISTRY }}
99+
severity: 'CRITICAL,HIGH'
100+
detailed-severity: 'CRITICAL,HIGH,MEDIUM,LOW'
101+
ignore-unfixed: 'true'
102+
exit-code: '0'
103+
artifact-name: 'security-scan-results'
104+
artifact-retention-days: '30'
105+
github-token: ${{ secrets.GITHUB_TOKEN }}
106+
post-pr-comment: 'true'
107+
108+
# Optional: Handle scan results programmatically
109+
- name: Process scan results
110+
run: |
111+
echo "Security scan status: ${{ steps.security-scan.outputs.scan-status }}"
112+
echo "Vulnerabilities found: ${{ steps.security-scan.outputs.vulnerability-count }}"
113+
echo "Artifact ID: ${{ steps.security-scan.outputs.artifact-id }}"
114+
115+
# You can add custom logic here based on the scan results
116+
if [ "${{ steps.security-scan.outputs.scan-status }}" = "vulnerabilities_found" ]; then
117+
echo "⚠️ Security vulnerabilities detected!"
118+
echo "Consider reviewing the security report before deploying."
119+
120+
# Optionally, you could fail the build for critical vulnerabilities:
121+
# if [ "${{ steps.security-scan.outputs.vulnerability-count }}" -gt "10" ]; then
122+
# echo "❌ Too many vulnerabilities found (> 10), failing build"
123+
# exit 1
124+
# fi
125+
else
126+
echo "✅ No critical or high severity vulnerabilities found!"
127+
fi
91128
92129
- name: Container info
93130
if: success()

0 commit comments

Comments
 (0)