Add image signing, SBOM generation, and vulnerability scanning to CI/CD
Some checks failed
CI/CD Pipeline - Apartment API / Run Tests (push) Successful in 9m42s
CI/CD Pipeline - Apartment API / Deploy to Production (push) Has been cancelled
CI/CD Pipeline - Apartment API / Build & Push Image (push) Has been cancelled

- Add Trivy vulnerability scanning (fails on CRITICAL/HIGH)
- Add Syft SBOM generation in SPDX format
- Add Cosign image signing using digest
- Attach SBOM attestation to image in Harbor
- Add cosign.pub for signature verification
This commit is contained in:
2026-01-23 14:55:01 -07:00
parent ad5555d759
commit 2d7b412c1a
2 changed files with 65 additions and 0 deletions

View File

@ -85,6 +85,7 @@ jobs:
password: ${{ secrets.HARBOR_PASSWORD }} password: ${{ secrets.HARBOR_PASSWORD }}
- name: Build and push Docker image - name: Build and push Docker image
id: build-push
uses: docker/build-push-action@v5 uses: docker/build-push-action@v5
with: with:
context: . context: .
@ -93,6 +94,66 @@ jobs:
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:${{ steps.set-tag.outputs.tag }} ${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:${{ steps.set-tag.outputs.tag }}
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:latest ${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:latest
# ============================================================
# Vulnerability Scanning with Trivy
# ============================================================
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master
with:
image-ref: ${{ steps.set-tag.outputs.full_image }}
format: 'table'
exit-code: '1'
ignore-unfixed: true
vuln-type: 'os,library'
severity: 'CRITICAL,HIGH'
- name: Run Trivy and output SARIF
uses: aquasecurity/trivy-action@master
if: always()
with:
image-ref: ${{ steps.set-tag.outputs.full_image }}
format: 'sarif'
output: 'trivy-results.sarif'
# ============================================================
# SBOM Generation with Syft
# ============================================================
- name: Generate SBOM with Syft
uses: anchore/sbom-action@v0
with:
image: ${{ steps.set-tag.outputs.full_image }}
format: spdx-json
output-file: sbom.spdx.json
# ============================================================
# Image Signing with Cosign
# ============================================================
- name: Install Cosign
uses: sigstore/cosign-installer@v3
- name: Sign image with Cosign
env:
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
run: |
cosign sign --key env://COSIGN_PRIVATE_KEY \
--yes \
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}@${{ steps.build-push.outputs.digest }}
# ============================================================
# Attach SBOM to image in Harbor
# ============================================================
- name: Attach SBOM to image
env:
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
run: |
cosign attest --key env://COSIGN_PRIVATE_KEY \
--type spdxjson \
--predicate sbom.spdx.json \
--yes \
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}@${{ steps.build-push.outputs.digest }}
# ============================================================ # ============================================================
# Deploy Job - Pull image and restart on production server # Deploy Job - Pull image and restart on production server
# ============================================================ # ============================================================

4
cosign.pub Normal file
View File

@ -0,0 +1,4 @@
-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEBOFl4SHzoZVM59+668t2tecTyKM+
cE4zaOkbFO30u7d2+bjpwPnbYrTutKmAeehYzCAVW/OYea7ML0cW2YCSCQ==
-----END PUBLIC KEY-----