Skip to content

Security Scan

Security Scan #7

Workflow file for this run

#
# Licensed to the Apache Software Foundation (ASF) under one or more
# contributor license agreements. See the NOTICE file distributed with
# this work for additional information regarding copyright ownership.
# The ASF licenses this file to You under the Apache License, Version 2.0
# (the "License"); you may not use this file except in compliance with
# the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
name: Security Scan
on:
pull_request:
schedule:
- cron: '0 0 * * 0' # Weekly on Sunday at midnight UTC
permissions:
contents: read
security-events: write
jobs:
trivy-config-scan:
name: Trivy Chart Configuration Scan
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- name: Run Trivy config scan
uses: aquasecurity/trivy-action@18f2510ee396bbf400402947b394f2dd8c87dbb0 # v0.30.0
with:
scan-type: 'config'
scan-ref: 'charts/devlake'
severity: 'HIGH,CRITICAL'
format: 'sarif'
output: 'trivy-results.sarif'
exit-code: '1' # Fail on HIGH/CRITICAL findings (enforcement mode)
- name: Upload Trivy results to Security tab
uses: github/codeql-action/upload-sarif@df40e58635f26fcf0f2bd0aa91b61c82dae084f0 # v3
if: always()
with:
sarif_file: 'trivy-results.sarif'
kubescape-scan:
name: Kubescape Security Best Practices
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- name: Install mise
uses: jdx/mise-action@1648a7812b9aeae629881980618f079932869151 # v4
- name: Install tools via mise
run: mise install
- name: Add Helm repos
run: |
helm repo add grafana https://grafana.github.io/helm-charts
helm repo update
- name: Build chart dependencies
run: |
helm dependency build charts/devlake
- name: Template Helm chart
run: |
helm template devlake charts/devlake > rendered-manifests.yaml
- name: Run Kubescape scan
uses: kubescape/github-action@66899c2b07e9ba6ca6f3f7e4decc7e2485f1f7cb # v3.0.3
with:
format: sarif
outputFile: kubescape-results.sarif
files: rendered-manifests.yaml
# Enforcement mode enabled: scan will fail on security violations
- name: Upload Kubescape results to Security tab
uses: github/codeql-action/upload-sarif@df40e58635f26fcf0f2bd0aa91b61c82dae084f0 # v3
if: always()
with:
sarif_file: 'kubescape-results.sarif'