Add scan-backend workflow: build image and run trivy scan
This commit is contained in:
@@ -0,0 +1,91 @@
|
|||||||
|
name: 'Scan Backend Image'
|
||||||
|
run-name: '${{ inputs.repo_path }} → trivy [${{ inputs.branch }}]'
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
inputs:
|
||||||
|
repo_path:
|
||||||
|
description: 'Репозиторий'
|
||||||
|
required: true
|
||||||
|
type: choice
|
||||||
|
options:
|
||||||
|
- devspace-apiregistry-core-service
|
||||||
|
- devspace-apiregistry-generator-service
|
||||||
|
- devspace-gateway
|
||||||
|
- devspace-api
|
||||||
|
default: devspace-apiregistry-core-service
|
||||||
|
branch:
|
||||||
|
description: 'Ветка'
|
||||||
|
required: true
|
||||||
|
type: string
|
||||||
|
default: master
|
||||||
|
jobs:
|
||||||
|
scan:
|
||||||
|
name: 'Trivy scan'
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: 'Print Info'
|
||||||
|
run: |
|
||||||
|
echo "Repository: ${{ github.event.inputs.repo_path }}"
|
||||||
|
echo "Branch: ${{ github.event.inputs.branch }}"
|
||||||
|
- name: Cloning
|
||||||
|
uses: https://git.binom.pw/otp/devops/clone@main
|
||||||
|
with:
|
||||||
|
ssh-private-key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||||
|
repository: "devspc/${{ github.event.inputs.repo_path }}"
|
||||||
|
branch: ${{ github.event.inputs.branch }}
|
||||||
|
- uses: https://git.binom.pw/otp/devops/config-gradle@main
|
||||||
|
- uses: https://git.binom.pw/otp/devops/setup-gradle@main
|
||||||
|
- name: Setup Jvm
|
||||||
|
uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
java-version: 21
|
||||||
|
distribution: "adopt"
|
||||||
|
- name: Building
|
||||||
|
run: |
|
||||||
|
./gradlew bootJar --no-daemon -x cyclonedxBom
|
||||||
|
echo 'Jar in libs folder'
|
||||||
|
ls ./build/libs
|
||||||
|
- name: Generate Dockerfile
|
||||||
|
run: |
|
||||||
|
cat > ./Dockerfile << 'EOF'
|
||||||
|
FROM eclipse-temurin:21-jre-alpine
|
||||||
|
|
||||||
|
COPY /build/libs/*.jar /app.jar
|
||||||
|
|
||||||
|
ENTRYPOINT ["java", "-jar", "/app.jar"]
|
||||||
|
EOF
|
||||||
|
- name: Build Image
|
||||||
|
uses: redhat-actions/buildah-build@v2
|
||||||
|
env:
|
||||||
|
RUNNER_OS: Linux
|
||||||
|
with:
|
||||||
|
image: "otp/devspc/${{ github.event.inputs.repo_path }}"
|
||||||
|
tags: scan
|
||||||
|
containerfiles: |
|
||||||
|
./Dockerfile
|
||||||
|
oci: true
|
||||||
|
tls-verify: false
|
||||||
|
context: .
|
||||||
|
extra-args: |
|
||||||
|
--retry=7
|
||||||
|
- name: Export Image to tar
|
||||||
|
run: |
|
||||||
|
buildah push "otp/devspc/${{ github.event.inputs.repo_path }}:scan" docker-archive:/tmp/image.tar
|
||||||
|
ls -lh /tmp/image.tar
|
||||||
|
- name: Install Trivy
|
||||||
|
run: |
|
||||||
|
curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin
|
||||||
|
trivy --version
|
||||||
|
- name: Scan Image
|
||||||
|
run: |
|
||||||
|
trivy image --input /tmp/image.tar \
|
||||||
|
--scanners vuln,secret,misconfig \
|
||||||
|
--format table
|
||||||
|
- name: 'Cleanup'
|
||||||
|
if: always()
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
echo 'Cleaning...'
|
||||||
|
rm -rf ~/.gradle/init.gradle.kts
|
||||||
|
rm -rf ~/.ssh/config
|
||||||
|
rm -rf ~/.ssh/my_key
|
||||||
Reference in New Issue
Block a user