-
Notifications
You must be signed in to change notification settings - Fork 93
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Use a tool to scan the k8s manifest and dockerfile #106
Comments
https://www.checkov.io/ seems to be a good candidate it's licensed under apache so free to use. |
Checkov has been added to the pipeline. |
Using Trivy in GHA for scanning dockerfile |
Dockerfile, helm & k8s SAST scan capabilities are added but is configured to fail only for CRITICAL Vulnerabilities. A separate Security vulnerability](#351) issue has been created for fixing the vulnerabiities Hence closing this Issue as completed. |
Identity a security tooling to scan the k8s manifest (standard and helm charts) locally and Dockerfile for security recommendations.
The text was updated successfully, but these errors were encountered: