Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Code Security and container image vulnerability scanning #3813

Open
6 tasks
santhosh-tg opened this issue May 7, 2023 · 9 comments
Open
6 tasks

Code Security and container image vulnerability scanning #3813

santhosh-tg opened this issue May 7, 2023 · 9 comments

Comments

@santhosh-tg
Copy link
Collaborator

Project Details:

We currently perform only code quality check on Coverage using sonarcloud.

Code security is an important aspect using which we will be able to identify security issues and vulnerabilities during the development phase.

Along with code security we must also implement docker container scanning for vulnerabilities .Docker image vulnerability scanning could be defined as identifying known security vulnerabilities in the packages listed in the Docker image. Vulnerability scanning allows us to find vulnerabilities in container images and fix them before using or pushing the image to the registry.

Features be to be implemented:

Code security scan on code.

Containerimage vulnerability scanning.

Learning Path

Complexity: Medium

Skills Required: DevOps

Name of Mentors:
@santhosh-tg

Project size:
TBD

Project repos:

https://github.com/project-sunbird/sunbird-devops/

https://github.com/Sunbird-Ed/

Acceptance Criteria:

Code security and container image vulnerability scanning is setup

Milestones

  • Understanding the requirements
  • Research on the tools needed
  • Setting up the tools
  • Integration of the tools
  • Testing
  • Documentation
@wasup-yash
Copy link

wasup-yash commented May 12, 2023

hey i want to work on this issue

@SuperAayush
Copy link

Hey @santhosh-tg!!

Looking forward to submitting a proposal for the project.

@jiyanpatil07
Copy link

@santhosh-tg
I'm interested to be a part of this project, Looking forward to submitting a proposal for the same.
Do let me know if there is any requirement from my side.
Thank You.

@vyankateshOdilwar
Copy link

Having deep understanding in Testing, Looking forward to work in this project.

@godofgeeks23
Copy link

@santhosh-tg i have some prior experience in container and code security. Would love to contribute in this project.

@lakkidivinay01
Copy link

@santhosh-tg I would love to contribute to this project

@bhavyastar
Copy link

Hey @santhosh-tg!!

Looking forward to submitting a proposal for the project.

@aakanksha1801
Copy link

hello sir, I wanted to work with you and submit a proposal for this project

@rudrakshi-gupta
Copy link

Hey @santhosh-tg ,
This project excites me into leveraging the skills and learning that I learned for DevOps. Totally up for this project.
Count me in as a participant submitting a proposal for the same.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

10 participants