Skip to content

[CI] Add Docker image hardening and vulnerability scan workflow #245

@utksh1

Description

@utksh1

Problem

SecuScan needs a production-grade improvement in this area: Container release safety..

Scope

Scan backend/frontend images, fail on critical vulnerabilities, check non-root user, and document base-image update policy.

Acceptance Criteria

  • The implementation is focused and does not introduce unrelated UI, docs, lockfile, or formatting churn.
  • Security-sensitive behavior has explicit negative tests where applicable.
  • Existing tests continue to pass, and new tests cover the main success and failure paths.
  • Documentation or configuration examples are updated when operator behavior changes.

Verification

CI should publish vulnerability reports and fail on a synthetic or known critical baseline only when policy requires.

Difficulty

Hard, useful issue intended for experienced contributors.

Metadata

Metadata

Assignees

Labels

area:ciCI, tooling, or automation workarea:securitySecurity-sensitive implementation or testslevel:advanced55 pts difficulty label for advanced contributor PRspriority:highHigh-priority issuetype:devopsDevOps or infrastructure work category bonus labeltype:securitySecurity work category bonus label

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions