Skip to content
@security-chain-demo

security-chain-demo

Software Supply Chain Security – Demo

This is a Proof-of-Concept showing how to incorporate fixing security vulnerabilities without any additional software you have to buy. It only uses

  • GitHub Actions
  • JIRA (we assume, you already use that as an issue tracker)

When doing a deployment, the GitHub Actions pipeline will scan for vulnerabilities with Trivy, and sync the found issues to JIRA.

In JIRA they can be handled within the usual workflow. In addition, a Grafana dashboard can visualize the data.

For more information, see the repositories

Pinned

  1. deployment deployment Public

    Handles deployments

  2. github-actions github-actions Public

    Holds GitHub Actions

Repositories

Showing 3 of 3 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…