Update .github/workflows/deploy.yml
All checks were successful
CI/CD Pipeline - Apartment Dashboard / Run Linter (push) Successful in 12s
CI/CD Pipeline - Apartment Dashboard / Scan Dependencies (push) Successful in 12s
CI/CD Pipeline - Apartment Dashboard / Build & Push Image (push) Successful in 32s
CI/CD Pipeline - Apartment Dashboard / Deploy to Production (push) Successful in 14s

This commit is contained in:
2026-02-08 19:54:43 -07:00
parent 3a6a735872
commit f0b1ea3e05

View File

@ -106,66 +106,66 @@ jobs:
# ============================================================ # ============================================================
# Vulnerability Scanning with Trivy # Vulnerability Scanning with Trivy
# ============================================================ # ============================================================
- name: Install Trivy # - name: Install Trivy
run: | # run: |
curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin v0.58.0 # curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin v0.58.0
- name: Run Trivy vulnerability scanner # - name: Run Trivy vulnerability scanner
run: | # run: |
trivy image \ # trivy image \
--exit-code 1 \ # --exit-code 1 \
--ignore-unfixed \ # --ignore-unfixed \
--vuln-type os,library \ # --vuln-type os,library \
--severity CRITICAL,HIGH \ # --severity CRITICAL,HIGH \
--format table \ # --format table \
${{ steps.set-tag.outputs.full_image }} # ${{ steps.set-tag.outputs.full_image }}
- name: Run Trivy and output SARIF # - name: Run Trivy and output SARIF
if: always() # if: always()
run: | # run: |
trivy image \ # trivy image \
--format sarif \ # --format sarif \
--output trivy-results.sarif \ # --output trivy-results.sarif \
${{ steps.set-tag.outputs.full_image }} || true # ${{ steps.set-tag.outputs.full_image }} || true
# ============================================================ # ============================================================
# SBOM Generation with Syft # SBOM Generation with Syft
# ============================================================ # ============================================================
- name: Generate SBOM with Syft # - name: Generate SBOM with Syft
uses: anchore/sbom-action@v0 # uses: anchore/sbom-action@v0
with: # with:
image: ${{ steps.set-tag.outputs.full_image }} # image: ${{ steps.set-tag.outputs.full_image }}
format: spdx-json # format: spdx-json
output-file: sbom.spdx.json # output-file: sbom.spdx.json
# ============================================================ # ============================================================
# Image Signing with Cosign # Image Signing with Cosign
# ============================================================ # ============================================================
- name: Install Cosign # - name: Install Cosign
uses: sigstore/cosign-installer@v3 # uses: sigstore/cosign-installer@v3
- name: Sign image with Cosign # - name: Sign image with Cosign
env: # env:
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }} # COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }} # COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
run: | # run: |
cosign sign --key env://COSIGN_PRIVATE_KEY \ # cosign sign --key env://COSIGN_PRIVATE_KEY \
--yes \ # --yes \
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}@${{ steps.build-push.outputs.digest }} # ${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}@${{ steps.build-push.outputs.digest }}
# ============================================================ # ============================================================
# Attach SBOM to image in Harbor # Attach SBOM to image in Harbor
# ============================================================ # ============================================================
- name: Attach SBOM to image # - name: Attach SBOM to image
env: # env:
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }} # COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }} # COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
run: | # run: |
cosign attest --key env://COSIGN_PRIVATE_KEY \ # cosign attest --key env://COSIGN_PRIVATE_KEY \
--type spdxjson \ # --type spdxjson \
--predicate sbom.spdx.json \ # --predicate sbom.spdx.json \
--yes \ # --yes \
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}@${{ steps.build-push.outputs.digest }} # ${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}@${{ steps.build-push.outputs.digest }}
# ============================================================ # ============================================================
# Deploy Job - Pull image and restart on production server # Deploy Job - Pull image and restart on production server