Skip to content

Commit

Permalink
Debug ci pipeline 2 (#153)
Browse files Browse the repository at this point in the history
* Fix more ci pipeline yaml

* Rework snyk reporting to Kosli
  • Loading branch information
JonJagger committed Feb 29, 2024
1 parent 0cb0210 commit 8e6c4e1
Show file tree
Hide file tree
Showing 2 changed files with 22 additions and 36 deletions.
29 changes: 11 additions & 18 deletions .github/workflows/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -177,29 +177,22 @@ jobs:
- name: Setup Snyk
uses: snyk/actions/setup@master

- name: Run Snyk to check Docker image for vulnerabilities
continue-on-error: true
- name: Run Snyk container scan and report results to Kosli Trail
env:
KOSLI_ATTACHMENTS: /tmp/kosli_attachments
run: |
KOSLI_ATTACHMENTS=/tmp/kosli
rm -rf "${KOSLI_ATTACHMENTS}" || true
mkdir -p "${KOSLI_ATTACHMENTS}"
cp .snyk "${KOSLI_ATTACHMENTS}"
snyk container test "${IMAGE_NAME}"
--file=Dockerfile
--sarif
--sarif-file-output=snyk.container.scan.json
set +e
snyk container test "${IMAGE_NAME}" \
--file=Dockerfile \
--sarif \
--sarif-file-output=snyk.container.scan.json \
--policy-path=.snyk | tee "${KOSLI_ATTACHMENTS}/snyk.container.scan.log
set -e
- name: Attest Snyk results to Kosli Trail
run: |
env | grep KOSLI_ATTACHMENTS || true
KOSLI_ATTACHMENTS=/tmp/kosli
ls -al /tmp
ls -al "${KOSLI_ATTACHMENTS}"
kosli attest snyk "${IMAGE_NAME}"
--name=dashboard.snyk-container-scan
kosli attest snyk "${IMAGE_NAME}" \
--name=dashboard.snyk-container-scan \
--scan-results=snyk.container.scan.json
Expand Down
29 changes: 11 additions & 18 deletions .github/workflows/main_staging.yml
Original file line number Diff line number Diff line change
Expand Up @@ -167,29 +167,22 @@ jobs:
- name: Setup Snyk
uses: snyk/actions/setup@master

- name: Run Snyk to check Docker image for vulnerabilities
continue-on-error: true
- name: Run Snyk container scan and report results to Kosli Trail
env:
KOSLI_ATTACHMENTS: /tmp/kosli_attachments
run: |
KOSLI_ATTACHMENTS=/tmp/kosli
rm -rf "${KOSLI_ATTACHMENTS}" || true
mkdir -p "${KOSLI_ATTACHMENTS}"
cp .snyk "${KOSLI_ATTACHMENTS}"
snyk container test "${IMAGE_NAME}"
--file=Dockerfile
--sarif
--sarif-file-output=snyk.container.scan.json
set +e
snyk container test "${IMAGE_NAME}" \
--file=Dockerfile \
--sarif \
--sarif-file-output=snyk.container.scan.json \
--policy-path=.snyk | tee "${KOSLI_ATTACHMENTS}/snyk.container.scan.log
set -e
- name: Attest Snyk results to Kosli Trail
run: |
env | grep KOSLI_ATTACHMENTS || true
KOSLI_ATTACHMENTS=/tmp/kosli
ls -al /tmp
ls -al "${KOSLI_ATTACHMENTS}"
kosli attest snyk "${IMAGE_NAME}"
--name=dashboard.snyk-container-scan
kosli attest snyk "${IMAGE_NAME}" \
--name=dashboard.snyk-container-scan \
--scan-results=snyk.container.scan.json
Expand Down

0 comments on commit 8e6c4e1

Please sign in to comment.