Add scan-backend workflow: build image and run trivy scan
This commit is contained in:
@@ -0,0 +1,91 @@
|
||||
name: 'Scan Backend Image'
|
||||
run-name: '${{ inputs.repo_path }} → trivy [${{ inputs.branch }}]'
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
repo_path:
|
||||
description: 'Репозиторий'
|
||||
required: true
|
||||
type: choice
|
||||
options:
|
||||
- devspace-apiregistry-core-service
|
||||
- devspace-apiregistry-generator-service
|
||||
- devspace-gateway
|
||||
- devspace-api
|
||||
default: devspace-apiregistry-core-service
|
||||
branch:
|
||||
description: 'Ветка'
|
||||
required: true
|
||||
type: string
|
||||
default: master
|
||||
jobs:
|
||||
scan:
|
||||
name: 'Trivy scan'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: 'Print Info'
|
||||
run: |
|
||||
echo "Repository: ${{ github.event.inputs.repo_path }}"
|
||||
echo "Branch: ${{ github.event.inputs.branch }}"
|
||||
- name: Cloning
|
||||
uses: https://git.binom.pw/otp/devops/clone@main
|
||||
with:
|
||||
ssh-private-key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||
repository: "devspc/${{ github.event.inputs.repo_path }}"
|
||||
branch: ${{ github.event.inputs.branch }}
|
||||
- uses: https://git.binom.pw/otp/devops/config-gradle@main
|
||||
- uses: https://git.binom.pw/otp/devops/setup-gradle@main
|
||||
- name: Setup Jvm
|
||||
uses: actions/setup-java@v4
|
||||
with:
|
||||
java-version: 21
|
||||
distribution: "adopt"
|
||||
- name: Building
|
||||
run: |
|
||||
./gradlew bootJar --no-daemon -x cyclonedxBom
|
||||
echo 'Jar in libs folder'
|
||||
ls ./build/libs
|
||||
- name: Generate Dockerfile
|
||||
run: |
|
||||
cat > ./Dockerfile << 'EOF'
|
||||
FROM eclipse-temurin:21-jre-alpine
|
||||
|
||||
COPY /build/libs/*.jar /app.jar
|
||||
|
||||
ENTRYPOINT ["java", "-jar", "/app.jar"]
|
||||
EOF
|
||||
- name: Build Image
|
||||
uses: redhat-actions/buildah-build@v2
|
||||
env:
|
||||
RUNNER_OS: Linux
|
||||
with:
|
||||
image: "otp/devspc/${{ github.event.inputs.repo_path }}"
|
||||
tags: scan
|
||||
containerfiles: |
|
||||
./Dockerfile
|
||||
oci: true
|
||||
tls-verify: false
|
||||
context: .
|
||||
extra-args: |
|
||||
--retry=7
|
||||
- name: Export Image to tar
|
||||
run: |
|
||||
buildah push "otp/devspc/${{ github.event.inputs.repo_path }}:scan" docker-archive:/tmp/image.tar
|
||||
ls -lh /tmp/image.tar
|
||||
- name: Install Trivy
|
||||
run: |
|
||||
curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin
|
||||
trivy --version
|
||||
- name: Scan Image
|
||||
run: |
|
||||
trivy image --input /tmp/image.tar \
|
||||
--scanners vuln,secret,misconfig \
|
||||
--format table
|
||||
- name: 'Cleanup'
|
||||
if: always()
|
||||
shell: bash
|
||||
run: |
|
||||
echo 'Cleaning...'
|
||||
rm -rf ~/.gradle/init.gradle.kts
|
||||
rm -rf ~/.ssh/config
|
||||
rm -rf ~/.ssh/my_key
|
||||
Reference in New Issue
Block a user