numerique-gouv / people

Teams management application
MIT License
13 stars 1 forks source link

✨(ci) add security scan #429

Closed rouja closed 2 weeks ago

rouja commented 1 month ago

Add a security scan for CVE with trivy

Morendil commented 3 weeks ago

See #500 for a version of this PR without the fixes applied, showing the Trivy report with CVEs.

Morendil commented 2 weeks ago

After discussion with @mjeammet a good solution would be to make this an optional check in CI. Will look into that.