Releases: billhoph/DevSecOps
Release list
v20.2.0-build.22
Automated DevSecOps build
Version: 20.2.0 (build #22)
Commit: dffe267
Container image
- Tag:
v20.2.0-build.22 - Digest:
sha256:233a8adbbf890f5ac6301c5890cd9fe1502c38339f990206ea880e51491a09f9 - Pushed to Docker Hub (
joanjoho/devsecops) and Google Artifact Registry.
Full registry refs and the Cloud Run URL are on the run's Summary page
(image refs embed private identifiers, so they are omitted from public notes).
Security gates (report-only — Juice Shop is intentionally vulnerable)
- 🔑 Secrets — Gitleaks · 🔍 SAST — Semgrep · 📦 SCA — Trivy (fs + image) · 🛡️ Image — Grype · 🧾 SBOM — Syft
Full SARIF results are in the repo Security tab and attached to this release.
🧪 Security scan summary
| Stage | Tool | 🟥 Critical | 🟧 High | 🟨 Medium | 🟦 Low | Total |
|---|---|---|---|---|---|---|
| Secrets | Gitleaks | 0 | 66 | 0 | 0 | 66 |
| Image | Grype | 9 | 45 | 40 | 5 | 99 |
| SAST | Semgrep | 0 | 18 | 47 | 3 | 68 |
| Image | Trivy | 7 | 48 | 42 | 13 | 110 |
| SCA (deps) | Trivy | 20 | 25 | 9 | 40 | 94 |
| Total | 36 | 202 | 138 | 61 | 437 |
SBOM (Syft, CycloneDX): source: 68 components · image: 2688 components
Findings are report-only (Juice Shop is intentionally vulnerable). Full details are in the Security ▸ Code scanning tab and attached to the release.
Full Changelog: v20.2.0-build.17...v20.2.0-build.22
v20.2.0-build.21
Automated DevSecOps build
Version: 20.2.0 (build #21)
Commit: 2fb9f28
Container image
- Tag:
v20.2.0-build.21 - Digest:
sha256:9ad51c9225c9a9b28e815c72a3341c385d4dbd3e7b702e0f9fda6af9db9cf794 - Pushed to Docker Hub (
joanjoho/devsecops) and Google Artifact Registry.
Full registry refs and the Cloud Run URL are on the run's Summary page
(image refs embed private identifiers, so they are omitted from public notes).
Security gates (report-only — Juice Shop is intentionally vulnerable)
- 🔑 Secrets — Gitleaks · 🔍 SAST — Semgrep · 📦 SCA — Trivy (fs + image) · 🛡️ Image — Grype · 🧾 SBOM — Syft
Full SARIF results are in the repo Security tab and attached to this release.
🧪 Security scan summary
| Stage | Tool | 🟥 Critical | 🟧 High | 🟨 Medium | 🟦 Low | Total |
|---|---|---|---|---|---|---|
| Secrets | Gitleaks | 0 | 66 | 0 | 0 | 66 |
| Image | Grype | 9 | 45 | 40 | 4 | 98 |
| SAST | Semgrep | 0 | 18 | 47 | 3 | 68 |
| Image | Trivy | 7 | 48 | 42 | 12 | 109 |
| SCA (deps) | Trivy | 20 | 25 | 9 | 40 | 94 |
| Total | 36 | 202 | 138 | 59 | 435 |
SBOM (Syft, CycloneDX): source: 68 components · image: 2688 components
Findings are report-only (Juice Shop is intentionally vulnerable). Full details are in the Security ▸ Code scanning tab and attached to the release.
Full Changelog: v20.2.0-build.15...v20.2.0-build.21
v20.2.0-build.17
Automated DevSecOps build
Version: 20.2.0 (build #17)
Commit: 2fb9f28
Container image
- Tag:
v20.2.0-build.17 - Digest:
sha256:8d67c0ed747e9f2e584ec30f05e9b84a4a6879bdca817a80cd7d694efdf3aa0c - Pushed to Docker Hub (
joanjoho/devsecops) and Google Artifact Registry.
Full registry refs and the Cloud Run URL are on the run's Summary page
(image refs embed private identifiers, so they are omitted from public notes).
Security gates (report-only — Juice Shop is intentionally vulnerable)
- 🔑 Secrets — Gitleaks · 🔍 SAST — Semgrep · 📦 SCA — Trivy (fs + image) · 🛡️ Image — Grype · 🧾 SBOM — Syft
Full SARIF results are in the repo Security tab and attached to this release.
🧪 Security scan summary
| Stage | Tool | 🟥 Critical | 🟧 High | 🟨 Medium | 🟦 Low | Total |
|---|---|---|---|---|---|---|
| Secrets | Gitleaks | 0 | 66 | 0 | 0 | 66 |
| Image | Grype | 9 | 45 | 40 | 4 | 98 |
| SAST | Semgrep | 0 | 18 | 47 | 3 | 68 |
| Image | Trivy | 7 | 48 | 42 | 12 | 109 |
| SCA (deps) | Trivy | 20 | 25 | 9 | 40 | 94 |
| Total | 36 | 202 | 138 | 59 | 435 |
SBOM (Syft, CycloneDX): source: 68 components · image: 2688 components
Findings are report-only (Juice Shop is intentionally vulnerable). Full details are in the Security ▸ Code scanning tab and attached to the release.
Full Changelog: v20.2.0-build.15...v20.2.0-build.17
v20.2.0-build.15
Automated DevSecOps build
Version: 20.2.0 (build #15)
Commit: 8222f30
Container image
- Tag:
v20.2.0-build.15 - Digest:
sha256:a8e53da7dcb82cdc68e098242b38ba796c8af794108250b43496b2dbc14ece68 - Pushed to Docker Hub (
joanjoho/devsecops) and Google Artifact Registry.
Full registry refs and the Cloud Run URL are on the run's Summary page
(image refs embed private identifiers, so they are omitted from public notes).
Security gates (report-only — Juice Shop is intentionally vulnerable)
- 🔑 Secrets — Gitleaks · 🔍 SAST — Semgrep · 📦 SCA — Trivy (fs + image) · 🛡️ Image — Grype · 🧾 SBOM — Syft
Full SARIF results are in the repo Security tab and attached to this release.
🧪 Security scan summary
| Stage | Tool | 🟥 Critical | 🟧 High | 🟨 Medium | 🟦 Low | Total |
|---|---|---|---|---|---|---|
| Secrets | Gitleaks | 0 | 66 | 0 | 0 | 66 |
| Image | Grype | 9 | 45 | 40 | 4 | 98 |
| SAST | Semgrep | 0 | 18 | 47 | 3 | 68 |
| Image | Trivy | 7 | 48 | 42 | 12 | 109 |
| SCA (deps) | Trivy | 20 | 25 | 9 | 40 | 94 |
| Total | 36 | 202 | 138 | 59 | 435 |
SBOM (Syft, CycloneDX): source: 68 components · image: 2688 components
Findings are report-only (Juice Shop is intentionally vulnerable). Full details are in the Security ▸ Code scanning tab and attached to the release.
Full Changelog: v20.2.0-build.14...v20.2.0-build.15
v20.2.0-build.14
Automated DevSecOps build
Version: 20.2.0 (build #14)
Commit: 560f440
Container image
- Tag:
v20.2.0-build.14 - Digest:
sha256:0bcf388068ddf36923610b0a56d7c70784107210eb28d64f15be75218478255e - Pushed to Docker Hub (
joanjoho/devsecops) and Google Artifact Registry.
Full registry refs and the Cloud Run URL are on the run's Summary page
(image refs embed private identifiers, so they are omitted from public notes).
Security gates (report-only — Juice Shop is intentionally vulnerable)
- 🔑 Secrets — Gitleaks
- 🔍 SAST — Semgrep
- 📦 SCA — Trivy (filesystem + image)
- 🧾 SBOM — Syft (source + image, CycloneDX & SPDX)
Full results are in the repo Security tab and attached below.
Full Changelog: v20.2.0-build.13...v20.2.0-build.14
v20.2.0-build.13
Automated DevSecOps build
Version: 20.2.0 (build #13)
Commit: ddf009a
Container image
- Tag:
v20.2.0-build.13 - Digest:
sha256:fdb65521da5b8ff5ef1dbb6aecea7678c5817736b5583ae8ad77092c245b6315 - Pushed to Docker Hub (
joanjoho/devsecops) and Google Artifact Registry.
Full registry refs and the Cloud Run URL are on the run's Summary page
(image refs embed private identifiers, so they are omitted from public notes).
Security gates (report-only — Juice Shop is intentionally vulnerable)
- 🔑 Secrets — Gitleaks
- 🔍 SAST — Semgrep
- 📦 SCA — Trivy (filesystem + image)
- 🧾 SBOM — Syft (source + image, CycloneDX & SPDX)
Full results are in the repo Security tab and attached below.
Full Changelog: v20.2.0-build.12...v20.2.0-build.13
v20.2.0-build.9
Automated DevSecOps build
Version: 20.2.0 (build #9)
Commit: 2b83cb5
Container image
- Tag:
v20.2.0-build.9 - Digest:
sha256:a6e19a01a60232f43091cd890997c63858761ba73f2e6cdb2d999c775763df4f - Pushed to Docker Hub (
joanjoho/devsecops) and Google Artifact Registry.
Full registry refs and the Cloud Run URL are on the run's Summary page
(image refs embed private identifiers, so they are omitted from public notes).
Security gates (report-only — Juice Shop is intentionally vulnerable)
- 🔑 Secrets — Gitleaks
- 🔍 SAST — Semgrep
- 📦 SCA — Trivy (filesystem + image)
- 🧾 SBOM — Syft (source + image, CycloneDX & SPDX)
Full results are in the repo Security tab and attached below.
Full Changelog: v20.2.0-build.8...v20.2.0-build.9
v20.2.0-build.8
Automated DevSecOps build
Version: 20.2.0 (build #8)
Commit: 08a8e6c
Container image
- Docker Hub: ``
- Artifact Registry: ``
- Digest:
sha256:2729fa499d5c5ded3dcd3ab5e9075fcaa7737f3bfd800e787d59b6346a20e774
Security gates (report-only — Juice Shop is intentionally vulnerable)
- 🔑 Secrets — Gitleaks
- 🔍 SAST — Semgrep
- 📦 SCA — Trivy (filesystem + image)
- 🧾 SBOM — Syft (source + image, CycloneDX & SPDX)
Full results are in the repo Security tab and attached below.
Full Changelog: https://github.com/billhoph/DevSecOps/commits/v20.2.0-build.8
v20.2.0-build.12
Automated DevSecOps build
Version: 20.2.0 (build #12)
Commit: 087f2d0
Container image
- Tag:
v20.2.0-build.12 - Digest:
sha256:626f0c83c0e5cfb1af83f0bc45bb733686f653219e96664bd67d3e76ad48eb96 - Pushed to Docker Hub (
joanjoho/devsecops) and Google Artifact Registry.
Full registry refs and the Cloud Run URL are on the run's Summary page
(image refs embed private identifiers, so they are omitted from public notes).
Security gates (report-only — Juice Shop is intentionally vulnerable)
- 🔑 Secrets — Gitleaks
- 🔍 SAST — Semgrep
- 📦 SCA — Trivy (filesystem + image)
- 🧾 SBOM — Syft (source + image, CycloneDX & SPDX)
Full results are in the repo Security tab and attached below.
Full Changelog: v20.2.0-build.11...v20.2.0-build.12
v20.2.0-build.11
Automated DevSecOps build
Version: 20.2.0 (build #11)
Commit: 47e3b23
Container image
- Tag:
v20.2.0-build.11 - Digest:
sha256:c4f6c4d740b3133ba21e603019a6a4edf6a42a472a2339ba1bf8e4871d523c57 - Pushed to Docker Hub (
joanjoho/devsecops) and Google Artifact Registry.
Full registry refs and the Cloud Run URL are on the run's Summary page
(image refs embed private identifiers, so they are omitted from public notes).
Security gates (report-only — Juice Shop is intentionally vulnerable)
- 🔑 Secrets — Gitleaks
- 🔍 SAST — Semgrep
- 📦 SCA — Trivy (filesystem + image)
- 🧾 SBOM — Syft (source + image, CycloneDX & SPDX)
Full results are in the repo Security tab and attached below.
Full Changelog: v20.2.0-build.10...v20.2.0-build.11