web-platform-tests / wpt.live

A live version of the web-platform-tests project
https://wpt.live/
15 stars 11 forks source link

Incorporate container image scanning and alerting for cert renewer and wpt server docker images #68

Open jcscottiii opened 2 years ago

jcscottiii commented 2 years ago

Building and deploying a docker container comes with maintaining the security of the image over time.

This repository needs a way to scan, alert or create and issue. Triggers could be on PR, push to main, and/or periodically

The risk by not doing this:

Pros:

example tool to scan (don't have to use this)