suxess-it / kubriX

https://kubrix.io
17 stars 3 forks source link

[security] scan new images in PR and check CVEs #752

Open jkleinlercher opened 4 days ago

jkleinlercher commented 4 days ago

With sth like https://github.com/marketplace/actions/container-scan ? see if CVEs increase with new version - compare PR with main

jkleinlercher commented 1 day ago

For helm security scanning (doesn’t scan images I guess): https://medium.com/@calvineotieno010/improving-your-ci-cd-pipeline-helm-charts-security-scanning-with-trivy-and-github-actions-acc081df2c2d