From 158c12796589aed2a901e6a10c9d59f95b9b4f78 Mon Sep 17 00:00:00 2001 From: Vladimir Gorej Date: Fri, 17 Sep 2021 14:19:21 +0300 Subject: [PATCH] chore(docker): automatic updates + nightly security check (#7515) Refs #7514 --- .github/_dependabot_.yaml | 35 ++++++++++++++---------- .github/workflows/docker-image-check.yml | 20 ++++++++++++++ 2 files changed, 41 insertions(+), 14 deletions(-) create mode 100644 .github/workflows/docker-image-check.yml diff --git a/.github/_dependabot_.yaml b/.github/_dependabot_.yaml index 027709b7..1def6c9d 100644 --- a/.github/_dependabot_.yaml +++ b/.github/_dependabot_.yaml @@ -1,16 +1,23 @@ version: 2 updates: -- package-ecosystem: npm - directory: "/" - schedule: - interval: daily - commit-message: - prefix: "chore" - include: "scope" - open-pull-requests-limit: 6 - ignore: - # node-fetch must be synced manually - - dependency-name: "node-fetch" - - dependency-name: "release-it" - - dependency-name: "@release-it/conventional-changelog" - + - package-ecosystem: npm + directory: "/" + schedule: + interval: daily + commit-message: + prefix: "chore" + include: "scope" + open-pull-requests-limit: 6 + ignore: + # node-fetch must be synced manually + - dependency-name: "node-fetch" + - dependency-name: "release-it" + - dependency-name: "@release-it/conventional-changelog" + + - package-ecosystem: "docker" + # Look for a `Dockerfile` in the `root` directory + directory: "/" + # Check for updates once a week + schedule: + interval: "weekly" + diff --git a/.github/workflows/docker-image-check.yml b/.github/workflows/docker-image-check.yml new file mode 100644 index 00000000..60588dd4 --- /dev/null +++ b/.github/workflows/docker-image-check.yml @@ -0,0 +1,20 @@ +name: Security scan for docker image + +on: + workflow_dispatch: + schedule: + - cron: '30 4 * * *' + +jobs: + build: + runs-on: ubuntu-latest + steps: + - name: Run Trivy vulnerability scanner + uses: aquasecurity/trivy-action@master + with: + image-ref: 'docker.io/swaggerapi/swagger-ui:unstable' + format: 'table' + exit-code: '1' + ignore-unfixed: true + vuln-type: 'os,library' + severity: 'CRITICAL,HIGH'