mirror of
https://github.com/grafana/grafana.git
synced 2025-02-25 18:55:37 -06:00
CI: scan master and release images oss/enterprise (#23475)
This commit is contained in:
parent
2c36137457
commit
f997f85eb7
@ -864,7 +864,7 @@ jobs:
|
||||
command: "./scripts/ci-job-succeeded.sh"
|
||||
when: on_success
|
||||
|
||||
scan-docker-master:
|
||||
scan-docker-images:
|
||||
docker:
|
||||
- image: circleci/buildpack-deps:stretch
|
||||
steps:
|
||||
@ -887,11 +887,29 @@ jobs:
|
||||
name: Clear trivy cache
|
||||
command: trivy --clear-cache
|
||||
- run:
|
||||
name: Scan the latest grafana master alpine image with trivy
|
||||
name: Scan grafana/grafana:master
|
||||
command: trivy --exit-code 1 grafana/grafana:master
|
||||
- run:
|
||||
name: Scan the latest grafana master ubuntu image with trivy
|
||||
name: Scan grafana/grafana:master-ubuntu
|
||||
command: trivy --exit-code 1 grafana/grafana:master-ubuntu
|
||||
- run:
|
||||
name: Scan grafana/grafana-enterprise:master
|
||||
command: trivy --exit-code 1 grafana/grafana-enterprise:master
|
||||
- run:
|
||||
name: Scan grafana/grafana-enterprise:master-ubuntu
|
||||
command: trivy --exit-code 1 grafana/grafana-enterprise:master-ubuntu
|
||||
- run:
|
||||
name: Scan grafana/grafana:latest
|
||||
command: trivy --exit-code 1 grafana/grafana:latest
|
||||
- run:
|
||||
name: Scan grafana/grafana:latest-ubuntu
|
||||
command: trivy --exit-code 1 grafana/grafana:latest-ubuntu
|
||||
- run:
|
||||
name: Scan grafana/grafana-enterprise:latest
|
||||
command: trivy --exit-code 1 grafana/grafana-enterprise:latest
|
||||
- run:
|
||||
name: Scan grafana/grafana-enterprise:latest-ubuntu
|
||||
command: trivy --exit-code 1 grafana/grafana-enterprise:latest-ubuntu
|
||||
- save_cache:
|
||||
key: vulnerability-db
|
||||
paths:
|
||||
@ -1227,4 +1245,4 @@ workflows:
|
||||
cron: "0 0 * * *"
|
||||
filters: *filter-only-master
|
||||
jobs:
|
||||
- scan-docker-master
|
||||
- scan-docker-images
|
||||
|
Loading…
Reference in New Issue
Block a user