Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

github actions: run daily trivy security scans on release docker image, composer/yarn dependencies #2047

Merged
merged 1 commit into from
Dec 3, 2023

Conversation

nodiscc
Copy link
Member

@nodiscc nodiscc commented Nov 26, 2023

@nodiscc nodiscc added enhancement security tools developer tools in review docker containers & cloud dependencies Pull requests that update a dependency file labels Nov 26, 2023
@nodiscc nodiscc added this to the 0.14.0 milestone Nov 26, 2023
…e, composer/yarn dependencies

- add badge to README
- any time a new vulnerability is found by this workflow, means it is probably time to update Shaarli's base docker image and perform a new release, and/or update npm dependencies (npm audit fix) or composer dependencies (composer update)
- similar jobs already exist in the pipeline for master/latest docker image but will not raise an error
- fixes shaarli#1531
@nodiscc nodiscc merged commit 709aba2 into shaarli:master Dec 3, 2023
8 checks passed
@nodiscc nodiscc deleted the trivy-schedule-release branch December 3, 2023 13:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file docker containers & cloud enhancement in review security tools developer tools
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Automate Docker images vulnerability scanning
1 participant