Repository navigation
v20.2.0-build.21
·
10 commits
to main
since this release
Automated DevSecOps build
Version: 20.2.0 (build #21)
Commit: 2fb9f28
Container image
- Tag:
v20.2.0-build.21 - Digest:
sha256:9ad51c9225c9a9b28e815c72a3341c385d4dbd3e7b702e0f9fda6af9db9cf794 - Pushed to Docker Hub (
joanjoho/devsecops) and Google Artifact Registry.
Full registry refs and the Cloud Run URL are on the run's Summary page
(image refs embed private identifiers, so they are omitted from public notes).
Security gates (report-only — Juice Shop is intentionally vulnerable)
- 🔑 Secrets — Gitleaks · 🔍 SAST — Semgrep · 📦 SCA — Trivy (fs + image) · 🛡️ Image — Grype · 🧾 SBOM — Syft
Full SARIF results are in the repo Security tab and attached to this release.
🧪 Security scan summary
| Stage | Tool | 🟥 Critical | 🟧 High | 🟨 Medium | 🟦 Low | Total |
|---|---|---|---|---|---|---|
| Secrets | Gitleaks | 0 | 66 | 0 | 0 | 66 |
| Image | Grype | 9 | 45 | 40 | 4 | 98 |
| SAST | Semgrep | 0 | 18 | 47 | 3 | 68 |
| Image | Trivy | 7 | 48 | 42 | 12 | 109 |
| SCA (deps) | Trivy | 20 | 25 | 9 | 40 | 94 |
| Total | 36 | 202 | 138 | 59 | 435 |
SBOM (Syft, CycloneDX): source: 68 components · image: 2688 components
Findings are report-only (Juice Shop is intentionally vulnerable). Full details are in the Security ▸ Code scanning tab and attached to the release.
Full Changelog: v20.2.0-build.15...v20.2.0-build.21