Skip to content

Update security scan workflow with new steps - #46

Open
martinrvisser wants to merge 1 commit into
mainfrom
martinrvisser-patch-3
Open

Update security scan workflow with new steps#46
martinrvisser wants to merge 1 commit into
mainfrom
martinrvisser-patch-3

Conversation

@martinrvisser

Copy link
Copy Markdown
Collaborator

Structure

Added name, on (push/PR to main), and wrapped job in jobs: key

Supply-chain hardening

Trivy installed via pinned release URL (0.51.1) + wget, no script pipes
Version check with trivy --version after install
Full commit SHAs on GitHub Actions (checkout, SARIF upload)

Efficiency

Single Trivy scan combining --format sarif --exit-code 1 (no redundant runs)
Scanning src/ only with trivy fs (not entire filesystem)
Removed noisy skip-dirs

Build gating

Trivy scan fails the build if CRITICAL/HIGH found (exit code 1)
Cppcheck errors explicitly fail with exit 1
SARIF still uploads via if: always() even on failure

Observability

Cppcheck results written to file and displayed
Error annotation in logs if Cppcheck finds issues
Clear success/fail output

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant