Re-enable security scanning and replace anchore/sbom-action with Syft CLI
All checks were successful
CI/CD Pipeline - Apartment Dashboard / Run Linter (push) Successful in 12s
CI/CD Pipeline - Apartment Dashboard / Scan Dependencies (push) Successful in 15s
CI/CD Pipeline - Apartment Dashboard / Deploy to Production (push) Successful in 14s
CI/CD Pipeline - Apartment Dashboard / Build & Push Image (push) Successful in 58s

Uncomment Trivy vulnerability scanning, Cosign image signing, and SBOM
attestation steps that were temporarily disabled. Replace the
anchore/sbom-action GitHub Action with direct Syft CLI install to avoid
the upload-artifact@v4 incompatibility with GHES.
This commit is contained in:
2026-02-08 20:20:42 -07:00
parent f0b1ea3e05
commit bd537a5e19

View File

@ -106,66 +106,67 @@ jobs:
# ============================================================ # ============================================================
# Vulnerability Scanning with Trivy # Vulnerability Scanning with Trivy
# ============================================================ # ============================================================
# - name: Install Trivy - name: Install Trivy
# run: | run: |
# curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin v0.58.0 curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin v0.58.0
# - name: Run Trivy vulnerability scanner - name: Run Trivy vulnerability scanner
# run: | run: |
# trivy image \ trivy image \
# --exit-code 1 \ --exit-code 1 \
# --ignore-unfixed \ --ignore-unfixed \
# --vuln-type os,library \ --vuln-type os,library \
# --severity CRITICAL,HIGH \ --severity CRITICAL,HIGH \
# --format table \ --format table \
# ${{ steps.set-tag.outputs.full_image }} ${{ steps.set-tag.outputs.full_image }}
# - name: Run Trivy and output SARIF - name: Run Trivy and output SARIF
# if: always() if: always()
# run: | run: |
# trivy image \ trivy image \
# --format sarif \ --format sarif \
# --output trivy-results.sarif \ --output trivy-results.sarif \
# ${{ steps.set-tag.outputs.full_image }} || true ${{ steps.set-tag.outputs.full_image }} || true
# ============================================================ # ============================================================
# SBOM Generation with Syft # SBOM Generation with Syft
# ============================================================ # ============================================================
# - name: Generate SBOM with Syft - name: Install Syft
# uses: anchore/sbom-action@v0 run: |
# with: curl -sSfL https://raw.githubusercontent.com/anchore/syft/main/install.sh | sh -s -- -b /usr/local/bin
# image: ${{ steps.set-tag.outputs.full_image }}
# format: spdx-json - name: Generate SBOM with Syft
# output-file: sbom.spdx.json run: |
syft ${{ steps.set-tag.outputs.full_image }} -o spdx-json=sbom.spdx.json
# ============================================================ # ============================================================
# Image Signing with Cosign # Image Signing with Cosign
# ============================================================ # ============================================================
# - name: Install Cosign - name: Install Cosign
# uses: sigstore/cosign-installer@v3 uses: sigstore/cosign-installer@v3
# - name: Sign image with Cosign - name: Sign image with Cosign
# env: env:
# COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }} COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
# COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }} COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
# run: | run: |
# cosign sign --key env://COSIGN_PRIVATE_KEY \ cosign sign --key env://COSIGN_PRIVATE_KEY \
# --yes \ --yes \
# ${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}@${{ steps.build-push.outputs.digest }} ${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}@${{ steps.build-push.outputs.digest }}
# ============================================================ # ============================================================
# Attach SBOM to image in Harbor # Attach SBOM to image in Harbor
# ============================================================ # ============================================================
# - name: Attach SBOM to image - name: Attach SBOM to image
# env: env:
# COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }} COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
# COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }} COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
# run: | run: |
# cosign attest --key env://COSIGN_PRIVATE_KEY \ cosign attest --key env://COSIGN_PRIVATE_KEY \
# --type spdxjson \ --type spdxjson \
# --predicate sbom.spdx.json \ --predicate sbom.spdx.json \
# --yes \ --yes \
# ${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}@${{ steps.build-push.outputs.digest }} ${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}@${{ steps.build-push.outputs.digest }}
# ============================================================ # ============================================================
# Deploy Job - Pull image and restart on production server # Deploy Job - Pull image and restart on production server