helxplatform / dug

Semantic Search
MIT License
32 stars 10 forks source link

Trivy action - CICD-198 #332

Closed joshua-seals closed 11 months ago

joshua-seals commented 1 year ago

CodeQL as part of Github will scan the repository code for each pull request action in checks that must be passed. Trivy will build the image as well as scan the codebase on each pull request, submitting it's report to Github Security Dashboard. High and Critical vulnerabilities will be flagged and the PR halted if discovered. Both CodeQL report and trivy should be viewable from the same panel in the dashboard.

github-advanced-security[bot] commented 1 year ago

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.