Add a security-scan action (secrets, dependencies, image) #19
Labels
No labels
priority/P0
priority/P1
priority/P2
priority/P3
size/L
size/M
size/S
size/XL
size/XS
state/done
state/in-progress
state/in-review
state/needs-refinement
state/ready
type/bug
type/chore
type/feature
type/refactor
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
amtronics/platform-actions#19
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Context
No repository pipeline scans for leaked secrets, vulnerable dependencies, or vulnerable container images. The trivy supply-chain compromises this year also showed why scanner tooling itself must be pinned and checksum-verified rather than pulled via vendor wrappers.
Scope
Acceptance criteria