Grype Severity-based CI enforcement - #326
Draft
SharkChar0255 wants to merge 2 commits into
Draft
Conversation
Contributor
Preview EnvironmentA preview environment can be spun up on demand for this PR.
|
Contributor
CI: Backend API
One or more checks failed. View logs |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR serves to update Grype's Enforcement to be Severity Based. At current, Grype is configured in such a way to NOT fail the CI job when vulnerabilities are identified.
As Grype supports a severity-based build enforcement, I intend to use that opportunity to extend the existing implementation from just vulnerability detection and reporting towards enforcement against detected vulnerabilities.
This change will make use of Grype's configuration options to fail the CI job when vulnerabilities are identified at a certain severity level.
This way, lower-severity findings can still be reported, but not fail CI checks, and higher-severity findings can halt CI in order to be tended to before merges. In doing this, we can extend the security control of Grype and strengthen AutoAudits overall security during CI.
Type of Change
Affected Components
/backend-api/frontend/engine(collectors / policies)/security/infrastructure/.github/workflows/docsMotivation
The motivation behind the change is to strengthen the existing vulnerability scanning workflow and improve security enforcement overall.
Planner Task
Testing Done
Security Considerations
As of current stage, no notable impacts on security.
Breaking Changes
Rollback Plan
Checklist