Skip to content

Commit

Permalink
Rename kosli snyk template name ready for adding code scanning (#149)
Browse files Browse the repository at this point in the history
  • Loading branch information
JonJagger committed Feb 29, 2024
1 parent 8be31bc commit 984fdd4
Show file tree
Hide file tree
Showing 3 changed files with 19 additions and 11 deletions.
14 changes: 9 additions & 5 deletions .github/workflows/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -180,18 +180,22 @@ jobs:
- name: Run Snyk to check Docker image for vulnerabilities
continue-on-error: true
run:
KOSLI_ATTACHMENTS=/tmp/kosli
rm -rf "${KOSLI_ATTACHMENTS}" || true
mkdir -p "${KOSLI_ATTACHMENTS}
cp .snyk "${KOSLI_ATTACHMENTS}

snyk container test "${IMAGE_NAME}"
--file=Dockerfile
--sarif
--sarif-file-output=snyk.json
--policy-path=.snyk
--sarif-file-output=snyk.container.scan.json
--policy-path=.snyk | tee "${KOSLI_ATTACHMENTS}/snyk.container.scan.log

- name: Attest Snyk results to Kosli Trail
run:
kosli attest snyk "${IMAGE_NAME}"
--attachments=.snyk
--name=dashboard.snyk-scan
--scan-results=snyk.json
--name=dashboard.snyk-container-scan
--scan-results=snyk.container.scan.json


sdlc-control-gate:
Expand Down
14 changes: 9 additions & 5 deletions .github/workflows/main_staging.yml
Original file line number Diff line number Diff line change
Expand Up @@ -170,18 +170,22 @@ jobs:
- name: Run Snyk to check Docker image for vulnerabilities
continue-on-error: true
run:
KOSLI_ATTACHMENTS=/tmp/kosli
rm -rf "${KOSLI_ATTACHMENTS}" || true
mkdir -p "${KOSLI_ATTACHMENTS}
cp .snyk "${KOSLI_ATTACHMENTS}

snyk container test "${IMAGE_NAME}"
--file=Dockerfile
--sarif
--sarif-file-output=snyk.json
--policy-path=.snyk
--sarif-file-output=snyk.container.scan.json
--policy-path=.snyk | tee "${KOSLI_ATTACHMENTS}/snyk.container.scan.log

- name: Attest Snyk results to Kosli Trail
run:
kosli attest snyk "${IMAGE_NAME}"
--attachments=.snyk
--name=dashboard.snyk-scan
--scan-results=snyk.json
--name=dashboard.snyk-container-scan
--scan-results=snyk.container.scan.json


sdlc-control-gate:
Expand Down
2 changes: 1 addition & 1 deletion .kosli.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@ trail:
type: generic
- name: pull-request
type: pull_request
- name: snyk-scan
- name: snyk-container-scan
type: snyk

0 comments on commit 984fdd4

Please sign in to comment.