Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Run Snyk docker security scans nightly #2055

Open
jackwotherspoon opened this issue Dec 4, 2023 · 3 comments
Open

Run Snyk docker security scans nightly #2055

jackwotherspoon opened this issue Dec 4, 2023 · 3 comments
Assignees
Labels
priority: p2 Moderately-important priority. Fix may not be included in next release. type: feature request ‘Nice-to-have’ improvement, new feature or different behavior or design.

Comments

@jackwotherspoon
Copy link
Collaborator

jackwotherspoon commented Dec 4, 2023

Add a Github Action to scan our published docker images nightly: https://github.com/snyk/actions/tree/master/docker

Action will notify the team if vulnerabilities have been found in any of the base images so that appropriate action (potential release with updated base image) can be taken.

@jackwotherspoon jackwotherspoon added priority: p2 Moderately-important priority. Fix may not be included in next release. type: feature request ‘Nice-to-have’ improvement, new feature or different behavior or design. labels Dec 4, 2023
@jackwotherspoon jackwotherspoon self-assigned this Dec 4, 2023
@enocom
Copy link
Member

enocom commented Dec 4, 2023

This would be in addition to the container scanning we do in Artifact Registry.

@enocom
Copy link
Member

enocom commented Dec 4, 2023

Also, we should port this to AlloyDB Auth Proxy as well.

@enocom
Copy link
Member

enocom commented Dec 4, 2023

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
priority: p2 Moderately-important priority. Fix may not be included in next release. type: feature request ‘Nice-to-have’ improvement, new feature or different behavior or design.
Projects
None yet
Development

No branches or pull requests

2 participants