GoogleCloudPlatform / cloud-sql-proxy

A utility for connecting securely to your Cloud SQL instances
Apache License 2.0
1.28k stars 350 forks source link

Run Snyk docker security scans nightly #2055

Open jackwotherspoon opened 12 months ago

jackwotherspoon commented 12 months ago

Add a Github Action to scan our published docker images nightly: https://github.com/snyk/actions/tree/master/docker

Action will notify the team if vulnerabilities have been found in any of the base images so that appropriate action (potential release with updated base image) can be taken.

enocom commented 12 months ago

This would be in addition to the container scanning we do in Artifact Registry.

enocom commented 12 months ago

Also, we should port this to AlloyDB Auth Proxy as well.

enocom commented 12 months ago

Cf. https://cloud.google.com/artifact-analysis/docs/os-scanning-on-demand