Skip to content

Compliance#758

Merged
sduchesneau merged 10 commits intodevelopfrom
compliance
May 1, 2026
Merged

Compliance#758
sduchesneau merged 10 commits intodevelopfrom
compliance

Conversation

@sduchesneau
Copy link
Copy Markdown
Contributor

@sduchesneau sduchesneau commented Apr 30, 2026

  • add dependency check on "secrets detection"
  • Add dependency check on dependabot
  • Add vulnerability checks in docker build with docker scout
  • Tweak branches and tags where each job runs to be more logical
  • Bump versions so it also fixes existing dependabot high/critical alerts

@sduchesneau
Copy link
Copy Markdown
Contributor Author

sduchesneau commented May 1, 2026

🔍 Vulnerabilities of ghcr.io/streamingfast/substreams:0047400

📦 Image Reference ghcr.io/streamingfast/substreams:0047400
digestsha256:63615285b77fa3abbaa297a000222789614f7a87456f94bf2d7424de53f98e87
vulnerabilitiescritical: 0 high: 0 medium: 0 low: 0
platformlinux/amd64
size115 MB
packages350
📦 Base Image ubuntu:24.04
also known as
  • 84bda043709f9066841484e9b8e440aa0d6d04ab49d09e367ef0fb68ace864cf
  • latest
  • noble
  • noble-20260410
digestsha256:cdb5fd928fced577cfecf12c8966e830fcdf42ee481fb0b91904eeddc2fe5eff
vulnerabilitiescritical: 0 high: 0 medium: 8 low: 2

@sduchesneau sduchesneau requested a review from UlysseCorbeil May 1, 2026 18:59
Copy link
Copy Markdown
Contributor

@UlysseCorbeil UlysseCorbeil left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Anything in this PR test_e2e related maybe should be in another PR of its own like "e2e tests improvements" or something, since it dosen't work and is out of scope, but minor bickering, otherwise lgtm

@sduchesneau sduchesneau merged commit b3c9c91 into develop May 1, 2026
6 checks passed
@UlysseCorbeil UlysseCorbeil deleted the compliance branch May 1, 2026 19:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants