From c91770d121d9f41b720220d5a2f62ec9cb69a633 Mon Sep 17 00:00:00 2001 From: Hermes Agent Date: Wed, 26 Aug 2026 12:24:17 +0300 Subject: [PATCH] Add scan-backend workflow: build image and run trivy scan --- .gitea/workflows/scan-backend.yml | 91 +++++++++++++++++++++++++++++++ 1 file changed, 91 insertions(+) create mode 100644 .gitea/workflows/scan-backend.yml diff --git a/.gitea/workflows/scan-backend.yml b/.gitea/workflows/scan-backend.yml new file mode 100644 index 0000000..029daba --- /dev/null +++ b/.gitea/workflows/scan-backend.yml @@ -0,0 +1,91 @@ +name: 'Scan Backend Image' +run-name: '${{ inputs.repo_path }} → trivy [${{ inputs.branch }}]' +on: + workflow_dispatch: + inputs: + repo_path: + description: 'Репозиторий' + required: true + type: choice + options: + - devspace-apiregistry-core-service + - devspace-apiregistry-generator-service + - devspace-gateway + - devspace-api + default: devspace-apiregistry-core-service + branch: + description: 'Ветка' + required: true + type: string + default: master +jobs: + scan: + name: 'Trivy scan' + runs-on: ubuntu-latest + steps: + - name: 'Print Info' + run: | + echo "Repository: ${{ github.event.inputs.repo_path }}" + echo "Branch: ${{ github.event.inputs.branch }}" + - name: Cloning + uses: https://git.binom.pw/otp/devops/clone@main + with: + ssh-private-key: ${{ secrets.SSH_PRIVATE_KEY }} + repository: "devspc/${{ github.event.inputs.repo_path }}" + branch: ${{ github.event.inputs.branch }} + - uses: https://git.binom.pw/otp/devops/config-gradle@main + - uses: https://git.binom.pw/otp/devops/setup-gradle@main + - name: Setup Jvm + uses: actions/setup-java@v4 + with: + java-version: 21 + distribution: "adopt" + - name: Building + run: | + ./gradlew bootJar --no-daemon -x cyclonedxBom + echo 'Jar in libs folder' + ls ./build/libs + - name: Generate Dockerfile + run: | + cat > ./Dockerfile << 'EOF' + FROM eclipse-temurin:21-jre-alpine + + COPY /build/libs/*.jar /app.jar + + ENTRYPOINT ["java", "-jar", "/app.jar"] + EOF + - name: Build Image + uses: redhat-actions/buildah-build@v2 + env: + RUNNER_OS: Linux + with: + image: "otp/devspc/${{ github.event.inputs.repo_path }}" + tags: scan + containerfiles: | + ./Dockerfile + oci: true + tls-verify: false + context: . + extra-args: | + --retry=7 + - name: Export Image to tar + run: | + buildah push "otp/devspc/${{ github.event.inputs.repo_path }}:scan" docker-archive:/tmp/image.tar + ls -lh /tmp/image.tar + - name: Install Trivy + run: | + curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin + trivy --version + - name: Scan Image + run: | + trivy image --input /tmp/image.tar \ + --scanners vuln,secret,misconfig \ + --format table + - name: 'Cleanup' + if: always() + shell: bash + run: | + echo 'Cleaning...' + rm -rf ~/.gradle/init.gradle.kts + rm -rf ~/.ssh/config + rm -rf ~/.ssh/my_key