-
Notifications
You must be signed in to change notification settings - Fork 97
Open
Labels
build/environmentCategorizes an issue or PR relevant to the build environment.Categorizes an issue or PR relevant to the build environment.good first issueDenotes an issue ready for a new contributorDenotes an issue ready for a new contributorhelp wantedDenotes an issue that needs help from a contributor.Denotes an issue that needs help from a contributor.kind/wishCategorizes issue or PR as a wish.Categorizes issue or PR as a wish.
Description
Add vulnerability scanning to the CI pipeline based on the generated SBOM.
Scope
- Scan SBOM build artefact for known vulnerabilities (CVE / CVSS)
- Use OSS tooling (e.g. grype, trivy, osv-scanner)
- Initial setup is report-only (no CI gating)
- Bonus: add CI gating for issues with a CVSS of 9 or higher.
tool recommendations are welcome.
Expected outcome
- CI job that performs vulnerability scanning
- Machine-readable scan output published as a CI artifact
- Short documentation describing:
- which tool is used
- what is (and is not) covered
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
build/environmentCategorizes an issue or PR relevant to the build environment.Categorizes an issue or PR relevant to the build environment.good first issueDenotes an issue ready for a new contributorDenotes an issue ready for a new contributorhelp wantedDenotes an issue that needs help from a contributor.Denotes an issue that needs help from a contributor.kind/wishCategorizes issue or PR as a wish.Categorizes issue or PR as a wish.