Skip to content

Releases: billhoph/DevSecOps

v20.2.0-build.22

Choose a tag to compare

@github-actions github-actions released this 29 Sep 11:44

Automated DevSecOps build

Version: 20.2.0 (build #22)
Commit: dffe267

Container image

  • Tag: v20.2.0-build.22
  • Digest: sha256:233a8adbbf890f5ac6301c5890cd9fe1502c38339f990206ea880e51491a09f9
  • Pushed to Docker Hub (joanjoho/devsecops) and Google Artifact Registry.
    Full registry refs and the Cloud Run URL are on the run's Summary page
    (image refs embed private identifiers, so they are omitted from public notes).

Security gates (report-only — Juice Shop is intentionally vulnerable)

  • 🔑 Secrets — Gitleaks · 🔍 SAST — Semgrep · 📦 SCA — Trivy (fs + image) · 🛡️ Image — Grype · 🧾 SBOM — Syft

Full SARIF results are in the repo Security tab and attached to this release.

🧪 Security scan summary

Stage Tool 🟥 Critical 🟧 High 🟨 Medium 🟦 Low Total
Secrets Gitleaks 0 66 0 0 66
Image Grype 9 45 40 5 99
SAST Semgrep 0 18 47 3 68
Image Trivy 7 48 42 13 110
SCA (deps) Trivy 20 25 9 40 94
Total 36 202 138 61 437

SBOM (Syft, CycloneDX): source: 68 components · image: 2688 components

Findings are report-only (Juice Shop is intentionally vulnerable). Full details are in the Security ▸ Code scanning tab and attached to the release.

Full Changelog: v20.2.0-build.17...v20.2.0-build.22

v20.2.0-build.21

Choose a tag to compare

@github-actions github-actions released this 28 Sep 03:10

Automated DevSecOps build

Version: 20.2.0 (build #21)
Commit: 2fb9f28

Container image

  • Tag: v20.2.0-build.21
  • Digest: sha256:9ad51c9225c9a9b28e815c72a3341c385d4dbd3e7b702e0f9fda6af9db9cf794
  • Pushed to Docker Hub (joanjoho/devsecops) and Google Artifact Registry.
    Full registry refs and the Cloud Run URL are on the run's Summary page
    (image refs embed private identifiers, so they are omitted from public notes).

Security gates (report-only — Juice Shop is intentionally vulnerable)

  • 🔑 Secrets — Gitleaks · 🔍 SAST — Semgrep · 📦 SCA — Trivy (fs + image) · 🛡️ Image — Grype · 🧾 SBOM — Syft

Full SARIF results are in the repo Security tab and attached to this release.

🧪 Security scan summary

Stage Tool 🟥 Critical 🟧 High 🟨 Medium 🟦 Low Total
Secrets Gitleaks 0 66 0 0 66
Image Grype 9 45 40 4 98
SAST Semgrep 0 18 47 3 68
Image Trivy 7 48 42 12 109
SCA (deps) Trivy 20 25 9 40 94
Total 36 202 138 59 435

SBOM (Syft, CycloneDX): source: 68 components · image: 2688 components

Findings are report-only (Juice Shop is intentionally vulnerable). Full details are in the Security ▸ Code scanning tab and attached to the release.

Full Changelog: v20.2.0-build.15...v20.2.0-build.21

v20.2.0-build.17

Choose a tag to compare

@github-actions github-actions released this 28 Sep 02:49

Automated DevSecOps build

Version: 20.2.0 (build #17)
Commit: 2fb9f28

Container image

  • Tag: v20.2.0-build.17
  • Digest: sha256:8d67c0ed747e9f2e584ec30f05e9b84a4a6879bdca817a80cd7d694efdf3aa0c
  • Pushed to Docker Hub (joanjoho/devsecops) and Google Artifact Registry.
    Full registry refs and the Cloud Run URL are on the run's Summary page
    (image refs embed private identifiers, so they are omitted from public notes).

Security gates (report-only — Juice Shop is intentionally vulnerable)

  • 🔑 Secrets — Gitleaks · 🔍 SAST — Semgrep · 📦 SCA — Trivy (fs + image) · 🛡️ Image — Grype · 🧾 SBOM — Syft

Full SARIF results are in the repo Security tab and attached to this release.

🧪 Security scan summary

Stage Tool 🟥 Critical 🟧 High 🟨 Medium 🟦 Low Total
Secrets Gitleaks 0 66 0 0 66
Image Grype 9 45 40 4 98
SAST Semgrep 0 18 47 3 68
Image Trivy 7 48 42 12 109
SCA (deps) Trivy 20 25 9 40 94
Total 36 202 138 59 435

SBOM (Syft, CycloneDX): source: 68 components · image: 2688 components

Findings are report-only (Juice Shop is intentionally vulnerable). Full details are in the Security ▸ Code scanning tab and attached to the release.

Full Changelog: v20.2.0-build.15...v20.2.0-build.17

v20.2.0-build.15

Choose a tag to compare

@github-actions github-actions released this 27 Sep 07:06

Automated DevSecOps build

Version: 20.2.0 (build #15)
Commit: 8222f30

Container image

  • Tag: v20.2.0-build.15
  • Digest: sha256:a8e53da7dcb82cdc68e098242b38ba796c8af794108250b43496b2dbc14ece68
  • Pushed to Docker Hub (joanjoho/devsecops) and Google Artifact Registry.
    Full registry refs and the Cloud Run URL are on the run's Summary page
    (image refs embed private identifiers, so they are omitted from public notes).

Security gates (report-only — Juice Shop is intentionally vulnerable)

  • 🔑 Secrets — Gitleaks · 🔍 SAST — Semgrep · 📦 SCA — Trivy (fs + image) · 🛡️ Image — Grype · 🧾 SBOM — Syft

Full SARIF results are in the repo Security tab and attached to this release.

🧪 Security scan summary

Stage Tool 🟥 Critical 🟧 High 🟨 Medium 🟦 Low Total
Secrets Gitleaks 0 66 0 0 66
Image Grype 9 45 40 4 98
SAST Semgrep 0 18 47 3 68
Image Trivy 7 48 42 12 109
SCA (deps) Trivy 20 25 9 40 94
Total 36 202 138 59 435

SBOM (Syft, CycloneDX): source: 68 components · image: 2688 components

Findings are report-only (Juice Shop is intentionally vulnerable). Full details are in the Security ▸ Code scanning tab and attached to the release.

Full Changelog: v20.2.0-build.14...v20.2.0-build.15

v20.2.0-build.14

Choose a tag to compare

@github-actions github-actions released this 27 Sep 04:32

Automated DevSecOps build

Version: 20.2.0 (build #14)
Commit: 560f440

Container image

  • Tag: v20.2.0-build.14
  • Digest: sha256:0bcf388068ddf36923610b0a56d7c70784107210eb28d64f15be75218478255e
  • Pushed to Docker Hub (joanjoho/devsecops) and Google Artifact Registry.
    Full registry refs and the Cloud Run URL are on the run's Summary page
    (image refs embed private identifiers, so they are omitted from public notes).

Security gates (report-only — Juice Shop is intentionally vulnerable)

  • 🔑 Secrets — Gitleaks
  • 🔍 SAST — Semgrep
  • 📦 SCA — Trivy (filesystem + image)
  • 🧾 SBOM — Syft (source + image, CycloneDX & SPDX)

Full results are in the repo Security tab and attached below.

Full Changelog: v20.2.0-build.13...v20.2.0-build.14

v20.2.0-build.13

Choose a tag to compare

@github-actions github-actions released this 27 Sep 04:24

Automated DevSecOps build

Version: 20.2.0 (build #13)
Commit: ddf009a

Container image

  • Tag: v20.2.0-build.13
  • Digest: sha256:fdb65521da5b8ff5ef1dbb6aecea7678c5817736b5583ae8ad77092c245b6315
  • Pushed to Docker Hub (joanjoho/devsecops) and Google Artifact Registry.
    Full registry refs and the Cloud Run URL are on the run's Summary page
    (image refs embed private identifiers, so they are omitted from public notes).

Security gates (report-only — Juice Shop is intentionally vulnerable)

  • 🔑 Secrets — Gitleaks
  • 🔍 SAST — Semgrep
  • 📦 SCA — Trivy (filesystem + image)
  • 🧾 SBOM — Syft (source + image, CycloneDX & SPDX)

Full results are in the repo Security tab and attached below.

Full Changelog: v20.2.0-build.12...v20.2.0-build.13

v20.2.0-build.9

Choose a tag to compare

@github-actions github-actions released this 26 Sep 03:03

Automated DevSecOps build

Version: 20.2.0 (build #9)
Commit: 2b83cb5

Container image

  • Tag: v20.2.0-build.9
  • Digest: sha256:a6e19a01a60232f43091cd890997c63858761ba73f2e6cdb2d999c775763df4f
  • Pushed to Docker Hub (joanjoho/devsecops) and Google Artifact Registry.
    Full registry refs and the Cloud Run URL are on the run's Summary page
    (image refs embed private identifiers, so they are omitted from public notes).

Security gates (report-only — Juice Shop is intentionally vulnerable)

  • 🔑 Secrets — Gitleaks
  • 🔍 SAST — Semgrep
  • 📦 SCA — Trivy (filesystem + image)
  • 🧾 SBOM — Syft (source + image, CycloneDX & SPDX)

Full results are in the repo Security tab and attached below.

Full Changelog: v20.2.0-build.8...v20.2.0-build.9

v20.2.0-build.8

Choose a tag to compare

@github-actions github-actions released this 26 Sep 02:56

Automated DevSecOps build

Version: 20.2.0 (build #8)
Commit: 08a8e6c

Container image

  • Docker Hub: ``
  • Artifact Registry: ``
  • Digest: sha256:2729fa499d5c5ded3dcd3ab5e9075fcaa7737f3bfd800e787d59b6346a20e774

Security gates (report-only — Juice Shop is intentionally vulnerable)

  • 🔑 Secrets — Gitleaks
  • 🔍 SAST — Semgrep
  • 📦 SCA — Trivy (filesystem + image)
  • 🧾 SBOM — Syft (source + image, CycloneDX & SPDX)

Full results are in the repo Security tab and attached below.

Full Changelog: https://github.com/billhoph/DevSecOps/commits/v20.2.0-build.8

v20.2.0-build.12

Choose a tag to compare

@github-actions github-actions released this 26 Sep 12:55

Automated DevSecOps build

Version: 20.2.0 (build #12)
Commit: 087f2d0

Container image

  • Tag: v20.2.0-build.12
  • Digest: sha256:626f0c83c0e5cfb1af83f0bc45bb733686f653219e96664bd67d3e76ad48eb96
  • Pushed to Docker Hub (joanjoho/devsecops) and Google Artifact Registry.
    Full registry refs and the Cloud Run URL are on the run's Summary page
    (image refs embed private identifiers, so they are omitted from public notes).

Security gates (report-only — Juice Shop is intentionally vulnerable)

  • 🔑 Secrets — Gitleaks
  • 🔍 SAST — Semgrep
  • 📦 SCA — Trivy (filesystem + image)
  • 🧾 SBOM — Syft (source + image, CycloneDX & SPDX)

Full results are in the repo Security tab and attached below.

Full Changelog: v20.2.0-build.11...v20.2.0-build.12

v20.2.0-build.11

Choose a tag to compare

@github-actions github-actions released this 26 Sep 12:26

Automated DevSecOps build

Version: 20.2.0 (build #11)
Commit: 47e3b23

Container image

  • Tag: v20.2.0-build.11
  • Digest: sha256:c4f6c4d740b3133ba21e603019a6a4edf6a42a472a2339ba1bf8e4871d523c57
  • Pushed to Docker Hub (joanjoho/devsecops) and Google Artifact Registry.
    Full registry refs and the Cloud Run URL are on the run's Summary page
    (image refs embed private identifiers, so they are omitted from public notes).

Security gates (report-only — Juice Shop is intentionally vulnerable)

  • 🔑 Secrets — Gitleaks
  • 🔍 SAST — Semgrep
  • 📦 SCA — Trivy (filesystem + image)
  • 🧾 SBOM — Syft (source + image, CycloneDX & SPDX)

Full results are in the repo Security tab and attached below.

Full Changelog: v20.2.0-build.10...v20.2.0-build.11