Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat(ci): add periodic and ad hoc vulnerability scan
esp-idf-sbom allows to scan whole repository/directory for all possible manifest files(idf_component.yml, sbom.yml and its referenced manifests, .gitmodules) and check them for possible vulnerabilities based on the cpe variable in manifest. This adds scheduled scan at every midnight and also ad hoc(dispatch workflow) allowing to scan on demand. Simple message with overall status and job link is sent to mattermost channel via webhook specified with MATTERMOST_WEBHOOK secret. Signed-off-by: Frantisek Hrbata <[email protected]>
- Loading branch information