scripts/container_scan.sh: add container image CVE scanning#21795
scripts/container_scan.sh: add container image CVE scanning#21795kairosci wants to merge 1 commit into
Conversation
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: kairosci The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Hi @kairosci. Thanks for your PR. I'm waiting for a etcd-io member to verify that this patch is reasonable to test. If it is, they should reply with Tip We noticed you've done this a few times! Consider joining the org to skip this step and gain Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Signed-off-by: Alessio Attilio <attilio.alessio@protonmail.com>
e856166 to
af39ce4
Compare
|
@ArkaSaha30 @ivanvc I believe we already have such CVE scan against container image, correct? |
Add a script, Makefile target, and CI workflow to scan the container base image with Trivy for OS-level CVEs. etcd is built with CGO_ENABLED=0 and the existing govulncheck+CodeQL pipeline only covers Go vulnerabilities, so OS-level CVEs in the distroless base image were not detected. Closes #21252