You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
abhisheksr01
changed the title
[security(scope)] - [Brief description of the vulnerability]
security(trivy) - trivy iac job found vulnerabilities in the code
Dec 26, 2024
abhisheksr01
changed the title
security(trivy) - trivy iac job found vulnerabilities in the code
security(trivy) - fix IAC vulnerabilities found by trivy job in the code
Dec 26, 2024
Vulnerability Description
The Dockerfile, kubernetes and helm configs are failing when
trivy config
is executed in CI using the marketplace action.Steps to Reproduce
sast-iac-trivy-hadolint
job executes which scans the IAC for security vulnerabilitiesImpact
The pipeline fails because of vulnerabiliteis which imposes secutity risk.
Suggested Mitigation or Fix
Fix the code to mitigate static infra code analysis found by trivy.
CVSS Score (Optional):
Available in the CI execution
The text was updated successfully, but these errors were encountered: