Skip to content

git actions upgrade + add trivy - #39

Merged
laxmanchekka merged 7 commits into
mainfrom
vuln-fixes
Jun 21, 2023
Merged

laxmanchekka merged 7 commits into
mainfrom
vuln-fixes

Conversation

@laxmanchekka

Copy link
Copy Markdown
Contributor

Description

git actions upgrade + add trivy

@github-advanced-security

Copy link
Copy Markdown

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

Comment thread .github/workflows/pr-build.yml Outdated
- name: Run Trivy vulnerability scanner for kafka image
uses: hypertrace/github-actions/trivy-image-scan@main
id: trivy-scan-1
id: trivy-scan-kafka

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

id is not required.

Comment thread .github/workflows/pr-build.yml Outdated
- name: Run Trivy vulnerability scanner for kafka-zookeeper image
uses: hypertrace/github-actions/trivy-image-scan@main
id: trivy-scan-2
id: trivy-scan-kafka-zk

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

id is not required.

Comment thread .trivyignore
Comment thread .trivyignore
Comment thread Dockerfile Outdated
Comment thread Dockerfile Outdated
Comment thread Dockerfile Outdated
# TODO: port this similarly to kafka-zookeeper in order to share base layer
# The only assumption we make about this FROM is that it has a JRE in path
FROM adoptopenjdk/openjdk11:jre-11.0.18_10@sha256:3282670f5b315c731cb69d62b5d7eb195392be4a55d22a398c9ed1008490de7d
FROM adoptopenjdk/openjdk11:jre-11.0.19_7@sha256: a2160bc43c40d98324f43260344bf70f3a1d6a408d5dc005d2e6fb4f0f788ec4

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
FROM adoptopenjdk/openjdk11:jre-11.0.19_7@sha256: a2160bc43c40d98324f43260344bf70f3a1d6a408d5dc005d2e6fb4f0f788ec4
FROM adoptopenjdk/openjdk11:jre-11.0.19_7@sha256:a2160bc43c40d98324f43260344bf70f3a1d6a408d5dc005d2e6fb4f0f788ec4

@laxmanchekka
laxmanchekka merged commit d243d51 into main Jun 21, 2023
@laxmanchekka
laxmanchekka deleted the vuln-fixes branch June 21, 2023 18:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants