Uploaded image for project: 'Camunda Optimize'
  1. Camunda Optimize
  2. OPT-6770

Trigger Trivy check upon merging to master

    • S

      Trivy for docker image scanning: https://github.com/aquasecurity/trivy
      Snyk misses some stuff and there was one occasion where customers found a vulnerability that we hadn't seen. It is worth integrating such a check into our release process for added confidence.
      The Zeebe controller repo has this integrated already. Maybe we can learn/copy something here.
      The trivy check should get triggered when the pipeline does the smoketest for docker when merging to master

       

        This is the controller panel for Smart Panels app

            [OPT-6770] Trigger Trivy check upon merging to master

            I merged this so we can see if it works for us this way

            Michal Konopski added a comment - I merged this so we can see if it works for us this way

              Unassigned Unassigned
              giuliano.rodrigues-lima Giuliano Rodrigues Lima
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: