Fix security vulnerabilities and add early dependency scanning
Some checks failed
CI/CD Pipeline - Apartment API / Scan Dependencies (push) Successful in 18s
CI/CD Pipeline - Apartment API / Run Tests (push) Successful in 10m20s
CI/CD Pipeline - Apartment API / Build & Push Image (push) Failing after 3m8s
CI/CD Pipeline - Apartment API / Deploy to Production (push) Has been skipped

- Update to node:20-alpine base image
- Add apk upgrade to fix OS-level vulnerabilities
- Update npm to latest to fix bundled package vulnerabilities
- Add scan-deps job that runs in parallel with tests
- Replace deprecated --only=production with --omit=dev
This commit is contained in:
2026-01-23 16:10:45 -07:00
parent 3518a8344a
commit 8dfdfdc8bb
2 changed files with 31 additions and 3 deletions

View File

@ -50,13 +50,37 @@ jobs:
JWT_SECRET: test-jwt-secret-for-ci
NODE_ENV: test
# ============================================================
# Dependency Scan Job - Runs in parallel with tests
# ============================================================
scan-deps:
name: Scan Dependencies
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Install Trivy
run: |
curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin v0.58.0
- name: Scan dependencies for vulnerabilities
run: |
trivy fs \
--exit-code 1 \
--ignore-unfixed \
--severity CRITICAL,HIGH \
--scanners vuln \
.
# ============================================================
# Build & Push Job - Build image and push to Harbor
# ============================================================
build:
name: Build & Push Image
runs-on: ubuntu-latest
needs: test
needs: [test, scan-deps]
if: github.ref == 'refs/heads/main' && github.event_name != 'pull_request'
outputs: