v20.2.0-build.9
·
8 commits
to main
since this release
Automated DevSecOps build
Version: 20.2.0 (build #9)
Commit: 2b83cb5
Container image
- Tag:
v20.2.0-build.9 - Digest:
sha256:a6e19a01a60232f43091cd890997c63858761ba73f2e6cdb2d999c775763df4f - Pushed to Docker Hub (
joanjoho/devsecops) and Google Artifact Registry.
Full registry refs and the Cloud Run URL are on the run's Summary page
(image refs embed private identifiers, so they are omitted from public notes).
Security gates (report-only — Juice Shop is intentionally vulnerable)
- 🔑 Secrets — Gitleaks
- 🔍 SAST — Semgrep
- 📦 SCA — Trivy (filesystem + image)
- 🧾 SBOM — Syft (source + image, CycloneDX & SPDX)
Full results are in the repo Security tab and attached below.
Full Changelog: v20.2.0-build.8...v20.2.0-build.9