Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Scanning Official CKAN Docker Images for vulnerabilities #55

Open
kowh-ai opened this issue Apr 30, 2024 · 0 comments
Open

Scanning Official CKAN Docker Images for vulnerabilities #55

kowh-ai opened this issue Apr 30, 2024 · 0 comments

Comments

@kowh-ai
Copy link
Contributor

kowh-ai commented Apr 30, 2024

Create GitHub action(s) Workflow to run (maybe nightly) a vulnerability scan on the Official CKAN images in DockerHub

Create a report that can be view manually

What tool (or tools) should we use:

  1. Synk Container
  2. Trivy

Trivy seems to be a one of the better ones after rudimentary analysis of image scanners currently on the market

What about signing an image for added security?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

1 participant