diff --git a/.github/workflows/build_and_push.yml b/.github/workflows/build_and_push.yml index 96585ff1..c1257b04 100644 --- a/.github/workflows/build_and_push.yml +++ b/.github/workflows/build_and_push.yml @@ -75,7 +75,7 @@ jobs: docker push $REGISTRY/${{ matrix.image }}:latest - name: Generate ${{ matrix.image }} docker SBOM - uses: cds-snc/security-tools/.github/actions/generate-sbom@e8bfe289161e1a923f8bb153c57280abfa33eb22 # v1 + uses: cds-snc/security-tools/.github/actions/generate-sbom@00801dc7049671a1a9bfa25a11ef2c2709ca78ed # v1 with: dependency_track_api_key: ${{ secrets.DEPENDENCY_TRACK_API_KEY }} docker_image: $REGISTRY/${{ matrix.image }}:$GITHUB_SHA @@ -83,9 +83,10 @@ jobs: project_type: docker - name: Docker scan and SBOM to GitHub - uses: cds-snc/security-tools/.github/actions/docker-scan@e8bfe289161e1a923f8bb153c57280abfa33eb22 + uses: cds-snc/security-tools/.github/actions/docker-scan@00801dc7049671a1a9bfa25a11ef2c2709ca78ed with: docker_image: ${{ env.REGISTRY }}/${{ matrix.image }} + sbom_name: ${{ matrix.image }} token: ${{ secrets.GITHUB_TOKEN }} - name: Logout of Amazon ECR diff --git a/.github/workflows/ci_build_containers.yml b/.github/workflows/ci_build_containers.yml index 0d48bf3d..8a15eeb9 100644 --- a/.github/workflows/ci_build_containers.yml +++ b/.github/workflows/ci_build_containers.yml @@ -69,7 +69,7 @@ jobs: -t $REGISTRY/${{ matrix.image }}:latest . - name: Generate ${{ matrix.image }} docker SBOM - uses: cds-snc/security-tools/.github/actions/generate-sbom@e8bfe289161e1a923f8bb153c57280abfa33eb22 # v1 + uses: cds-snc/security-tools/.github/actions/generate-sbom@00801dc7049671a1a9bfa25a11ef2c2709ca78ed # v1 with: dependency_track_api_key: ${{ secrets.DEPENDENCY_TRACK_API_KEY }} docker_image: $REGISTRY/${{ matrix.image }}:latest @@ -77,9 +77,10 @@ jobs: project_type: docker - name: Docker scan and SBOM to GitHub - uses: cds-snc/security-tools/.github/actions/docker-scan@e8bfe289161e1a923f8bb153c57280abfa33eb22 + uses: cds-snc/security-tools/.github/actions/docker-scan@00801dc7049671a1a9bfa25a11ef2c2709ca78ed # v1 with: docker_image: ${{ env.REGISTRY }}/${{ matrix.image }} + sbom_name: ${{ matrix.image }} token: ${{ secrets.GITHUB_TOKEN }} - name: Logout of Amazon ECR diff --git a/images/cloud_asset_inventory/cartography/Dockerfile b/images/cloud_asset_inventory/cartography/Dockerfile index c201ce21..e8467b81 100644 --- a/images/cloud_asset_inventory/cartography/Dockerfile +++ b/images/cloud_asset_inventory/cartography/Dockerfile @@ -18,4 +18,4 @@ ENV PATH="/home/python/venv/bin:${PATH}" \ COPY --chown=python:python requirements.txt /home/python/cartography/requirements.txt RUN /home/python/venv/bin/pip install --no-cache-dir --requirement /home/python/cartography/requirements.txt -ENTRYPOINT ["/docker-entrypoint.sh"] \ No newline at end of file +ENTRYPOINT ["/docker-entrypoint.sh"] diff --git a/images/cloud_asset_inventory/sentinel_neo4j_forwarder/Dockerfile b/images/cloud_asset_inventory/sentinel_neo4j_forwarder/Dockerfile index 0488003f..fe3cf149 100644 --- a/images/cloud_asset_inventory/sentinel_neo4j_forwarder/Dockerfile +++ b/images/cloud_asset_inventory/sentinel_neo4j_forwarder/Dockerfile @@ -24,4 +24,4 @@ COPY --from=public.ecr.aws/cds-snc/aws-sentinel-connector:c1f02b3f747b80fc18ed10 # Entrypoint RUN chown -R app:app /app/ USER app -CMD ["python3", "/app/neo4j_to_sentinel.py"] \ No newline at end of file +CMD ["python3", "/app/neo4j_to_sentinel.py"] diff --git a/images/csp_violation_report_service/app/Dockerfile b/images/csp_violation_report_service/app/Dockerfile index e870dfe7..59cad991 100644 --- a/images/csp_violation_report_service/app/Dockerfile +++ b/images/csp_violation_report_service/app/Dockerfile @@ -33,4 +33,4 @@ RUN chmod 755 /app/entry.sh EXPOSE 8000 -ENTRYPOINT [ "/app/entry.sh" ] \ No newline at end of file +ENTRYPOINT [ "/app/entry.sh" ] diff --git a/images/csp_violation_report_service/purge_stale_reports/Dockerfile b/images/csp_violation_report_service/purge_stale_reports/Dockerfile index e23a4092..34381011 100644 --- a/images/csp_violation_report_service/purge_stale_reports/Dockerfile +++ b/images/csp_violation_report_service/purge_stale_reports/Dockerfile @@ -31,4 +31,4 @@ COPY bin/entry.sh /app/entry.sh RUN chmod 755 /app/entry.sh ENTRYPOINT [ "/app/entry.sh" ] -CMD [ "lambda.handler" ] \ No newline at end of file +CMD [ "lambda.handler" ]