Skip to content

Commit

Permalink
Merge branch 'main' into lbushi/flushQueue
Browse files Browse the repository at this point in the history
  • Loading branch information
lbushi25 authored May 14, 2024
2 parents 6dc0b51 + 07151fa commit d367bd7
Show file tree
Hide file tree
Showing 5 changed files with 63 additions and 37 deletions.
5 changes: 3 additions & 2 deletions .github/docker/ubuntu-22.04.Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -67,7 +67,8 @@ RUN /opt/install_dpcpp.sh
COPY install_libbacktrace.sh /opt/install_libbacktrace.sh
RUN /opt/install_libbacktrace.sh

# Add a new (non-root) 'user'
ENV USER user
# Add a new (non-root) 'test_user' and switch to it
ENV USER test_user
ENV USERPASS pass
RUN useradd -m "${USER}" -g sudo -p "$(mkpasswd ${USERPASS})"
USER test_user
34 changes: 0 additions & 34 deletions .github/workflows/hadolint.yml

This file was deleted.

5 changes: 4 additions & 1 deletion .github/workflows/labeler.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,11 +10,14 @@ concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
cancel-in-progress: true

permissions:
contents: read

jobs:
labeler:
permissions:
contents: read
pull-requests: write
runs-on: ubuntu-latest
steps:
- uses: actions/labeler@v5
- uses: actions/labeler@8558fd74291d67161a8a78ce36a881fa63b766a9 # v5.0.0
50 changes: 50 additions & 0 deletions .github/workflows/trivy.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
# Runs linter for Docker files
name: Trivy

on:
workflow_dispatch:
push:
pull_request:
paths:
- '.github/docker/*Dockerfile'
- '.github/workflows/trivy.yml'

concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
cancel-in-progress: true

permissions:
contents: read

jobs:
linux:
name: Trivy
runs-on: ubuntu-latest
permissions:
security-events: write

steps:
- name: Clone repo
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1

- name: Run Trivy
uses: aquasecurity/trivy-action@84384bd6e777ef152729993b8145ea352e9dd3ef # v0.17.0
with:
scan-type: 'config'
hide-progress: false
format: 'sarif'
output: 'trivy-results.sarif'
exit-code: 1 # Fail if issue found
# file with suppressions: .trivyignore (in root dir)

- name: Print report and trivyignore file
run: |
echo "### Trivy ignore content:"
cat .trivyignore
echo "### Trivy report:"
cat trivy-results.sarif
- name: Upload results
uses: github/codeql-action/upload-sarif@e8893c57a1f3a2b659b6b55564fdfdbbd2982911 # v3.24.0
with:
sarif_file: 'trivy-results.sarif'
6 changes: 6 additions & 0 deletions .trivyignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
# Docs: https://aquasecurity.github.io/trivy/latest/docs/configuration/filtering/#trivyignore

# In docker files:
# HEALTHCHECK is not required for development, nor in CI (failed docker = failed CI).
# We're not hosting any application with usage of the dockers.
AVD-DS-0026

0 comments on commit d367bd7

Please sign in to comment.