suxess-it / kubriX

https://kubrix.io
19 stars 3 forks source link

[security] scan new images in PR and check CVEs #752

Open jkleinlercher opened 1 month ago

jkleinlercher commented 1 month ago

With sth like https://github.com/marketplace/actions/container-scan ? see if CVEs increase with new version - compare PR with main

jkleinlercher commented 1 month ago

For helm security scanning (doesn’t scan images I guess): https://medium.com/@calvineotieno010/improving-your-ci-cd-pipeline-helm-charts-security-scanning-with-trivy-and-github-actions-acc081df2c2d